Urgent: Restrict Non-Admin Users from Viewing All Users in Azure

26652748 0 Reputation points
2025-03-18T18:58:16.7566667+00:00

Dear Team,

I need to modify the Azure profile for users who are not admins. Currently, students with an A3 license can view all users in the Office 365 admin panel without editing on it , which should not be the case.

Please assist in restricting their access as soon as possible. This is an urgent request.

Regards,

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,167 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Navya 17,490 Reputation points Microsoft External Staff
    2025-03-19T04:43:06.7433333+00:00

    Hi @26652748

    By default, Microsoft Entra ID (Azure AD) allows any user to access and read data about other users, which can potentially expose sensitive information.

    In Entra ID, you can restrict access to the default user settings that allow reading all user attributes. To do this, you need to set the "Read other users" permission to false. This setting is available only in Microsoft Graph and PowerShell.

    Setting this flag to $false prevents all non-admin users from reading user information from the directory. However, this flag does not prevent users from accessing information in other Microsoft services like Exchange Online. Additionally, Microsoft does not recommend setting this flag to $false.

    Connect-MgGraph -Scopes "Policy.ReadWrite.Authorization"
    $BodyParams = @{
        defaultUserRolePermissions = @{
            allowedToReadOtherUsers = $false
        }
    }
    Invoke-MgGraphRequest -Uri "https://graph.microsoft.com/beta/policies/authorizationPolicy/authorizationPolicy" -Method PATCH -Body $BodyParams 
    

    Once applied, non-admin users will see restricted access in the Entra Admin Center as shown below.

    User's image

    Hope this helps. Do let us know if you any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.