Access restrictions of Tenant in Azure

Ankush Bhatia 0 Reputation points
2023-02-03T04:43:04.1166667+00:00

Hi All,

we have bought a SaaS based product which is hosted on Microsoft Azure ( a tenant)

this product is going to store work related documents hence we wanted no one should be able to access it from personal laptop ( and download documents )

what are recommended ways by which this can be applied ?

thanks

Ankush

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,201 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,563 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 28,321 Reputation points Microsoft Employee
    2023-02-03T07:34:27.37+00:00

    @Ankush Bhatia Thank you for reaching out to us, As I understand you are looking for a solution for SaaS based product hosted in Azure and wanted to control the user activities based on the device.

    You can leverage Microsoft Defender for Cloud Apps session policies enable real-time session-level monitoring, affording you granular visibility into cloud apps and the ability to take different actions depending on the policy you set for a user session. Instead of allowing or blocking access completely, with session control you can allow access while monitoring the session and/or limit specific session activities using the reverse proxy capabilities of Conditional Access App Control.

    Reference:

    https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad

    Block download on untrusted devices - https://www.youtube.com/watch?v=awRpA1ziyTs&t=0s

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.