Regarding the setting to prohibit general users from accessing and signing in to the Administration Center

BCAzure01 25 Reputation points
2025-09-22T03:01:46.71+00:00

We are trying to verify whether two control methods are feasible to achieve the following objectives. We understand from past inquiries that control is not possible with only [1] or only [2], but we suspect that it may be possible to achieve the objectives by combining them. If there are any settings that we have missed or risks in achieving our objectives, we would appreciate it if you could let us know the correct settings and the correct method.

■ Purpose

  • I want to restrict the following two points for general employees, excluding IT department administrator accounts.

① Prevent sign-in to all Microsoft 365 admin centers.

② Prevent access to resources on all Microsoft 365 admin centers.

*Currently, even general employees can access the EntraID admin center.

■ Control Method

[1] Configure Conditional Access

Target Resources:

  • P1: Microsoft Admin Portals (for general employees, excluding administrator and emergency exit accounts).
  • P2: Windows Azure Service Management API (to prevent loopholes in Azure management, ARM, CLI, PowerShell, etc.)
  • P3: Windows Azure Active Directory (effectively covers low-privilege Graph scopes)

Access: Block

⇒ Initially set to "Report-Only Mode" and confirm the impact in advance. After excluding necessary users, set to "On."

[2] Enable "Restrict access to the Microsoft Entra admin center" in Entra user settings

Azure Role-based access control
Azure Role-based access control

An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.