An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
Regarding the setting to prohibit general users from accessing and signing in to the Administration Center
We are trying to verify whether two control methods are feasible to achieve the following objectives. We understand from past inquiries that control is not possible with only [1] or only [2], but we suspect that it may be possible to achieve the objectives by combining them. If there are any settings that we have missed or risks in achieving our objectives, we would appreciate it if you could let us know the correct settings and the correct method.
■ Purpose
- I want to restrict the following two points for general employees, excluding IT department administrator accounts.
① Prevent sign-in to all Microsoft 365 admin centers.
② Prevent access to resources on all Microsoft 365 admin centers.
*Currently, even general employees can access the EntraID admin center.
■ Control Method
[1] Configure Conditional Access
Target Resources:
- P1: Microsoft Admin Portals (for general employees, excluding administrator and emergency exit accounts).
- P2: Windows Azure Service Management API (to prevent loopholes in Azure management, ARM, CLI, PowerShell, etc.)
- P3: Windows Azure Active Directory (effectively covers low-privilege Graph scopes)
Access: Block
⇒ Initially set to "Report-Only Mode" and confirm the impact in advance. After excluding necessary users, set to "On."
[2] Enable "Restrict access to the Microsoft Entra admin center" in Entra user settings