How do you use a conditional access policy to block end users access to Admin Portals while allowing end users to download office from portal.office.com?

Brian Findlay 0 Reputation points
2024-05-01T05:32:50.71+00:00

Hi wonderful people

With portal.office.com now classed as an Admin Portal: From support
User's image

How do you use a conditional access policy to block end users access to Admin Portals while allowing end users to download office from portal.office.com?

Scenario:

CAP configured to block all access to Admin portals:
User's image

User's image

User logs in to https://www.microsoft365.com/ and clicks install:
User's image

and is presented with this:
User's image

Sign in logs indicate that the Microsoft office portal is classed as an admin portal:
User's image

If the Office 365 app is added to the exclusion:
User's image

Conditional access does not fire:
User's image

but the user is then allowed through but presented with:
User's image

If I add the user to the group that is excluded from the block policy everything loads as expected.

Any guidance would be appreciated.

Brian

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,793 questions
{count} votes