Forum Discussion
Rebekka Aalbers-de Jong
Feb 09, 2018Iron Contributor
How to prohibit normal users acces to other users AAD profile Authentication contact info-fields?
A customer recently pointed out that all users have permissions to use PowerShell (with added modules) to run Get-Msol User and can read all user info and groups. To be able to use Delve and other t...
VasilMichev
Feb 10, 2018MVP
That's the only option you have. The argument usually goes something like "well you can see all this info in on-premises AD too". And there aren't that many regular users that will try PowerShell anyway, the bigger issue here is some rogue user running scripts to collect this information, etc.
Rebekka Aalbers-de Jong
Feb 11, 2018Iron Contributor
One other question: do you know if it is possible to Set-MsolCompanySettings -UsersPermissionToReadOtherUsersEnabled $False for the organization and -UsersPermissionToReadOtherUsersEnabled $True fro a specific Security Group?
- VasilMichevFeb 11, 2018MVP
No, it's an org-wide setting. Until we get a proper RBAC support for AAD, that's your only option (and even when/if we do, I'm not sure it will cover "read" permissions).