Gongalong Posted January 24, 2019 Posted January 24, 2019 (edited) Hi folks, We provision Office 365 via RM Unify. A parent (who works in IT and uses Azure) accidentally discovered, as one of their children had been logged in to O365 via Unify, that if they then went to portal.azure.com they were able to see things like Active Directory. They can't do much there e.g. they can't reset a password, if anything. I know very little about Azure, so is this normal that an O365 user can get to Azure and see these sorts of things, or is this something that hasn't been locked down correctly? Thanks Edited January 24, 2019 by Gongalong
Mako Posted January 24, 2019 Posted January 24, 2019 You can block access to Azure from within Azure itself. In Azure AD, scroll down to Conditional Access > New Policy. Give it a name. Under "Assignments", click Users and Groups. Select "All Users" from the Include tab. On the Exclude tab, tick "Users and Groups" and select your account, plus any other administrators. This is vital else you'll lock yourself out. Click "Cloud Apps" > Select apps > find "Microsoft Azure Management". Under "Access Controls" click "Grant" > "Block access" Select "On" from "Enable Policy" at the bottom and create the policy. Anyone not on the exclude list will be denied access to the Azure AD portal. 1
Gongalong Posted January 25, 2019 Author Posted January 25, 2019 Fab, that's solved it. Thanks lots for the info!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now