Non-admin user accessing "All Devices" page

Ben Wilson 20 Reputation points
2024-12-08T04:36:16.84+00:00

At Azure AD Users Settings page, I set the default user permission "Restrict access to Microsoft Entra administration portal" to Yes. A non-admin user cannot access Entra admin menu page. However, this non-admin user can still access "All Devices" page - https://portal.azure.com/#view/Microsoft_AAD_Devices/DevicesMenuBlade/~/Devices/menuId~/null

Here are my questions:

  • Is this supposed to happen?
  • If yes, is there any explanation for making the info accessible by non-admin users?
  • If yes, how to block the non-admin user access?

Thank you.

Best regards,

Microsoft 365 and Office Install, redeem, activate For business Windows
Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Bandela Siri Chandana 3,055 Reputation points Microsoft External Staff Moderator
    2024-12-09T10:30:22.15+00:00

    Hi @Ben Wilson

    Thank you for posting your query on Microsoft Q&A.

    I understand that your non-admin user can still access to "All Devices" page even though in user permission "Restrict access to Microsoft Entra administration portal" is enabled to Yes.

    Non-admin users cannot view the device page since they have access restrictions to the Microsoft Entra administrative site, which I tested in my lab as well. It's possible that the user you're working with was assigned any custom role.

    Don't use this switch as a security measure. Instead, create a Conditional Access policy that targets Windows Azure Service Management API that blocks Non administrators access to Windows Azure Service Management APIl.

    Follow the document for more information: https://learn.microsoft.com/en-us/entra/fundamentals/users-default-permissions#restrict-member-users-default-permissions

    Hope this helps. Do let us know if you any further queries.


    If this answers your query, do click `Accept Answer` and `Yes` .

    Thanks,

    B. Siri Chandana.

     


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.