How to create different types of service accounts properly with no MFA?

Sage Mirror 220 Reputation points
2023-11-14T14:25:19.91+00:00

Hi,

I would like to remove both MFA and Self-password reset (to remove the MFA registration requirement) to some accounts that are used as "service accounts".

For instance, some of them are just shared mailboxes, some are meeting rooms accounts, and others are for enrollment in autopilot (used to connect for the autopilot hash to be sent to Intune).

However, I can't exclude them from the Self-password reset because there is no "exclude group" function in it, and it's a dynamic group which is included, and add a rule to not include members from another group is not doable from what I could read.

I thought about adding a specific attribute to exclude with the dynamic rules in the account properties, but I am not sure if this is the best way to do it.

Could you provide me with some info about how to create and manage those kind of accounts properly please?

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Akhilesh Vallamkonda 15,320 Reputation points Microsoft External Staff Moderator
    2023-11-15T12:04:52.4766667+00:00

    Hi @Sage Mirror

    Thank you for reaching us!
    For your query I understand that you are looking to remove MFA and self-password reset for some accounts that are used as "service accounts and you are unable to exclude group in Self-password reset.

    I understand your concern, that you want to exclude only a few accounts from the Self-Service Password Reset (SSPR) feature, but currently, the feature only allows you to include groups, not exclude them.
    Appreciate if you could share the feedback on our feedback recovery of access review via https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789which is closely monitored by our product team.
    However, as a work around you can consider using Conditional Access policies or custom attributes. you can create a Conditional Access policy that requires SSPR for all users, then create another policy that excludes the specific accounts from SSPR.

    Also, you could use custom attributes in Azure AD to flag the accounts you want to exclude, then use dynamic group membership rules to automatically include all accounts without this flag in the SSPR group.

    I hope this answer helps! If you have any further questions, please feel free to ask.

    Reference: https://techcommunity.microsoft.com/t5/azure/feature-request-account-exclusion-functionality-for-sspr-self/m-p/3061575

    https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/conditional-access-for-the-azure-ad-combined-mfa-and-password/ba-p/566348

    Thanks,

    Akhilesh.
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.