Conditional access ;block all cloud apps excluding devops and azure management sigin log interpretation.

HAZRAT, Ula 0 Reputation points
2023-06-30T07:31:54.51+00:00

We have conditional access policy in our organisation the block external user from accessing all apps except azure devops and azure management.

The conditional access works fine only that the resulting sign in logs are a bit confusing to the security analysts.

If I could kind get an explanation of why the blow happens.

In the below screenshot the user tries to access the azure portal (as shown in the application title) but is blocked by the conditional access.

IThe screenshot shows that the application the user is trying to access the azure portal and the policy blocks the access

In this imaged the user is still trying to access the azure portal but the conditional access does not apply

User's image

My question is what is the difference between the two azure portals or azure portal

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
5,085 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
915 questions
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,899 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,070 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 149.1K Reputation points MVP
    2023-06-30T11:33:11.04+00:00

    I can't tell what the issue is from those images, but I would point out that you can't separate Dev Ops from the Azure portal with a CA policy:

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-cloud-apps#microsoft-azure-management

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.