Is there a way to block "Microsoft Azure PowerShell" for all users?

Andy Goldberg 0 Reputation points
2024-03-14T20:59:31.23+00:00

Greetings,

I'm afraid that this one can't be blocked by design, but I will ask anyway. Is there a way to block login attempt from Microsoft Azure PowerShell? We are constantly probed from all around the world, and I can't see to figure out how to block this. We are blocking all unused apps via Conditional Access Rules, plus there is a geolocation filter, but it kicks in only after successful authentication.

azure_powershell

azure_powershell2

Azure Information Protection
Azure Information Protection
An Azure service that is used to control and help secure email, documents, and sensitive data that are shared outside the company.
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Intune | Security
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marcin Policht 69,220 Reputation points MVP Volunteer Moderator
    2024-03-14T22:20:38.0766667+00:00

  2. Gudivada Adi Navya Sri 21,080 Reputation points Moderator
    2024-03-22T13:52:15.05+00:00

    Hi @Andy Goldberg

    Thank you for posting this in Microsoft Q&A.

    I understand that you want to know way to block "Microsoft Azure PowerShell" for all users.

    You can use conditional access policy or script to block Microsoft Azure PowerShell for all users in Entra. I noticed that you have already tried the conditional access policy.

    Please follow the steps which mentioned in this document: Blocking Powershell

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.