Entra ID Archives - Azure Security Architect https://azuresecurityarchitect.com/category/entra-id/ For all your cloud security needs Wed, 27 Nov 2024 18:13:19 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 214478653 Device Restrictions using Conditional Access Policies in Azure Entra ID https://azuresecurityarchitect.com/entra-id/device-restrictions-using-conditional-access-policies-in-azure-entra-id/ https://azuresecurityarchitect.com/entra-id/device-restrictions-using-conditional-access-policies-in-azure-entra-id/#respond Wed, 27 Nov 2024 18:13:19 +0000 https://azuresecurityarchitect.com/?p=270 Now, there’s a policy that allows you to restrict which devices get into your Azure subscriptions. The compliant devices policy requires you to list CIDR ranges/devices that are permitted. You […]

The post Device Restrictions using Conditional Access Policies in Azure Entra ID appeared first on Azure Security Architect.

]]>
Now, there’s a policy that allows you to restrict which devices get into your Azure subscriptions. The compliant devices policy requires you to list CIDR ranges/devices that are permitted. You can also make exceptions for specific devices if you need to.

The exact error

The portal encountered an issue while attempting to retrieve access tokens. We suggest attempting to sign in again, or alternatively, continuing without access tokens, although this may result in a suboptimal user experience. Additional details: invalid_grant: AADSTS530004: AcceptCompliantDevice setting isn’t configured for this organization. The admin needs to configure this setting to allow external users access to protected resources. Trace ID: af449c59-5668-4e01-9c12-6148328d6500 Correlation ID: e0318484-7e18-4c0f-b7a9-a678a9bc8cfd Timestamp: 2024-11-27 17:58:53Z.

The post Device Restrictions using Conditional Access Policies in Azure Entra ID appeared first on Azure Security Architect.

]]>
https://azuresecurityarchitect.com/entra-id/device-restrictions-using-conditional-access-policies-in-azure-entra-id/feed/ 0 270
Letting in vendors to your Entra Tenant https://azuresecurityarchitect.com/entra-id/letting-in-vendors-to-your-entra-tenant/ https://azuresecurityarchitect.com/entra-id/letting-in-vendors-to-your-entra-tenant/#respond Sat, 23 Nov 2024 00:26:33 +0000 https://azuresecurityarchitect.com/?p=263 Use Case Let in a set of Vendor Engineers into your Azure Subscription (typically with GLOBAL READER permissions) Steps in Entra and in Azure Set up SSO using the vendor’s […]

The post Letting in vendors to your Entra Tenant appeared first on Azure Security Architect.

]]>
Use Case

Let in a set of Vendor Engineers into your Azure Subscription (typically with GLOBAL READER permissions)

Steps in Entra and in Azure

  1. Set up SSO using the vendor’s email id as the UUID.
  2. Grant them GUEST User licenses – into your Entra Tenant
  3. Put all these VENDOR GUESTS into a single AAD User Group.
  4. Now use RBAC to grant this user group Azure resource permissions.

The post Letting in vendors to your Entra Tenant appeared first on Azure Security Architect.

]]>
https://azuresecurityarchitect.com/entra-id/letting-in-vendors-to-your-entra-tenant/feed/ 0 263
P2 licenses – Use Case – SSO Authentication and MFA – no mailbox https://azuresecurityarchitect.com/entra-id/licensing/p2-licenses-use-case-sso-authentication-and-mfa-no-mailbox/ https://azuresecurityarchitect.com/entra-id/licensing/p2-licenses-use-case-sso-authentication-and-mfa-no-mailbox/#respond Fri, 22 Nov 2024 20:36:46 +0000 https://azuresecurityarchitect.com/?p=257 Use Case – SSO Authentication and MFA – no mailbox P2 licenses – Cloud Only Authentication (not federated)

The post P2 licenses – Use Case – SSO Authentication and MFA – no mailbox appeared first on Azure Security Architect.

]]>
Use Case – SSO Authentication and MFA – no mailbox

P2 licenses – Cloud Only Authentication (not federated)

The post P2 licenses – Use Case – SSO Authentication and MFA – no mailbox appeared first on Azure Security Architect.

]]>
https://azuresecurityarchitect.com/entra-id/licensing/p2-licenses-use-case-sso-authentication-and-mfa-no-mailbox/feed/ 0 257