Conditional Access Policies to allow Guests to Teams

IMK 551 Reputation points
2024-11-01T10:10:13.36+00:00

Hi

We have a Conditiona Policy to require Compliant Device to access any data/app in MIcrosoft 365 cloud service. We have Microsoft 365 Business Premium licenses.

We have a need to allow Guest users to access Teams teams, they are invited to. For this, we need to change our Conditional Access Policies. We would need to allow only needed apps/services in Conditional Access Policies but problem is to find the correct ones.

I started by allowing guests to access "Office 365" app. According to

https://learn.microsoft.com/fi-fi/entra/identity/conditional-access/reference-office-365-application-contents

doc, allowing "Office 365" app, I allow many other apps that are not required to access Teams team, at least what I have understood.

But allowing guests to access "Office 365" app without Compliant Device requirement, is not enough. When I check Sign-in logs in Entra for some guest account, I can see that guests have problem of accessing Microsoft App Access Panel -application / Windows Azure Active Directory -resource. What I have understood, guests need access to this app/resource to set 2FA.

Problem here is that I can't allow guests access these app/resource because I can't add these to the Conditional Access Policy. These are not found when I try to add these to "Target Resources" of the policy by searching with "Microsoft" or "Microsoft App" or "Windows" or "Windows Azure" and so on so that I could exclude these from the Compliant Device requirement.

In other words, I need to allow guests to access all Microsoft 365 cloud apps and all resources in Microsoft 365 cloud just to get guests to be able to access Teams team, where they are invited to.

Is this really the situation or am I missing something? How this situation should be handled?

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
432 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,920 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 49,346 Reputation points Microsoft Vendor
    2024-11-04T01:52:06.1466667+00:00

    @IMK, Thanks for posting in Q&A. Based as I know, when configure MFA for Azure management in conditional access policy, the related resource is "Windows Azure Service Management API".

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-old-require-mfa-azure-mgmt#create-a-conditional-access-policy

    For the resource "Windows Azure Active Directory" in sign in log, it seems to be with this resource as well. Please configure "Windows Azure Service Management API" to be allowed in conditional access policy for these guests to see if the issue is resolved.

    User's image

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. IMK 551 Reputation points
    2024-11-04T16:21:40.0066667+00:00

    So I would need to allow Guest access for "Office 365" and "Windows Azure Service Management API" for Guests to be able to access Teams teams and to be able to register 2FA?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.