Entra user is able to sign in to an application to which he is not assigned

Marty Papesh 0 Reputation points
2025-04-10T21:52:23.7833333+00:00

Two of our external facing applications used for SSO are configured to only allow a limited set of users to access. User ******@cuone.org is not in the groups which have access to this application, yet he is able to use SSO on the external service to gain access. Need assistance remediating this issue and preventing this user account from accessing the external service.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.