Forum Discussion
How to avoid login to other tenants?
Adam,
At first, big thanks about your great answer!
Few ideas comes to my mind, I do not expect that Microsoft should be aware into which tenant I should go. But isn't great if we could define on the MDM/Intune that when EndUserA sign-in to our Skype-/Exchange online administrator could define into which tenant that user can go until with those apps? So I'm a bit wishing to see that applications can be aware of what is allowed to be done and what is not.
Also it is important to see that none of the solutions are bullet proofs, but sometimes some tiny block could save your day.
Whilst the options available right now are not as mature as you would like, the proxy solution https://docs.microsoft.com/en-gb/azure/active-directory/manage-apps/tenant-restrictions is a sound configuration. Saying that however, certain functions are unique to certain service workloads. For example you can block synchronisation of OneDrive for Business unless the workstation is on a specific domain as an example. This doesn't need Intune, it's available in the OneDrive for Business Admin Center.
In any case, expect protocols on how we access apps and data to change and evolve quite radically in the next 18 months.
- Brian ReidDec 09, 2018MVPMicrosoft is suggesting that you bypass proxies, but that is so that data access is not limited and cause applications to run slow. But to do tenant restrictions you need to proxy authentication traffic, and not all traffic - so you can do it and not impact performance, but it takes time and a good design