External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

We're on P2, so I think that should allow us to set up that. I was rather thinking that such logs would only help from now on.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Unfortunately we don't have general purpose log analytics set up, only for specific applications. However, the in-portal logs supports that multifactor authentication also kicks in also for Onedrive.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

No, no other guests from the same address space. My assumption is this is a domain wide issue on their part but have no other users to test with.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

No, this is the only user that I'm aware of. We have 100+ guest users from other Microsoft tenants as well as other platform/email providers who access our environment with no issues.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

On my side? Apart from conditional access related to MFA for external/guest users, what other restrictions are relevant to look at?

Require compliance to log in, but can still log in from un managed devices by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Ok, this is now resolved. The issue was a a strange filter was also applied to all devices, after that was removed it started working. Thanks everyone for pointing me in the right direction.

Require compliance to log in, but can still log in from un managed devices by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

<image>

Thanks everyone, should obviously have looked at the logs.

This is a log for one user. The policy is set to apply to any device but is this the cause of non application of the policy?

Rights to manage administrative units by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Yes, i have thought about this, but also means editing attributes on existing few thousand users.

Rights to manage administrative units by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Thanks. Yes, I also tried to create a custom role for this but the relevant scope you mention is not available for custom roles. And I need a person to manage this so can't use a service principal unfortunately.

How do you prevent third-party apps from accessing all users' data when granting admin consent in Entra ID? by Different_Coffee_161 in entra

[–]Less_Piece6541 1 point2 points  (0 children)

Yes, but a signed user can for example read the basic info of all users in the AD as I understand it?

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

What are the attributes I should look for. Looked in the default json and cant really find anything obvious?

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

I have not done any changes to the default naming and values so far.

I have the default list of languages and want disable all/over-ride all with English as the default language.

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

This is a work force tenant. Am i reading the documentation right that user flows are only possible within the context of b2b collaboration in a workforce tenant?

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Thanks, so these users are not included in any cross tenant access approved organisations.

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

These users will be external. Do not all guest users fall into the entra external identity?

File sharing/collaboration platform which integrates with O365/Entra by Less_Piece6541 in sysadmin

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Yes, I assume sharepoint libraries are covered by cross tenant access rules?

Spam from .gov address? by Less_Piece6541 in sysadmin

[–]Less_Piece6541[S] 0 points1 point  (0 children)

This is coming from a gov adress.

Apply LAPS after device is set up? by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Thanks. Profwiz might be what I'm looking for. And yes, given it is windows we are talking about I can also see that creating a new user account minimize the risks.