A cloud-based identity and access management service for securing user authentication and resource access
Hello Handian Sudianto,
Microsoft Entra ID does not provide a native feature to restrict a user's access to resources based on Azure subnets. For example, it cannot be configured to allow a user access only to resources in subnet 10.10.0.0/24 while blocking access to resources in other subnets.
This type of access control is typically implemented at the network or resource level:
- Use Network Security Groups (NSGs), Azure Firewall, or similar network controls to manage traffic between subnets.
- Use Conditional Access policies if the goal is to control where users can sign in from, such as specific IP ranges or trusted locations.
- Use Azure RBAC to control which Azure resources a user can access or manage.
The appropriate solution depends on the type of resources involved, such as VMs, applications, databases, or file shares. Additional details about the environment would help determine the most suitable approach.