Jump to content

Recommended Posts

Posted (edited)

Hi folks,

 

We provision Office 365 via RM Unify.

 

A parent (who works in IT and uses Azure) accidentally discovered, as one of their children had been logged in to O365 via Unify, that if they then went to portal.azure.com they were able to see things like Active Directory. They can't do much there e.g. they can't reset a password, if anything.

 

I know very little about Azure, so is this normal that an O365 user can get to Azure and see these sorts of things, or is this something that hasn't been locked down correctly?

 

Thanks

Edited by Gongalong
Posted

You can block access to Azure from within Azure itself.

 

  1. In Azure AD, scroll down to Conditional Access > New Policy. Give it a name.
  2. Under "Assignments", click Users and Groups. Select "All Users" from the Include tab. On the Exclude tab, tick "Users and Groups" and select your account, plus any other administrators. This is vital else you'll lock yourself out.
  3. Click "Cloud Apps" > Select apps > find "Microsoft Azure Management".
  4. Under "Access Controls" click "Grant" > "Block access"
  5. Select "On" from "Enable Policy" at the bottom and create the policy.

 

 

Anyone not on the exclude list will be denied access to the Azure AD portal.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...