Online Services available even if there are no Licenses issued

%3CLINGO-SUB%20id%3D%22lingo-sub-1152273%22%20slang%3D%22en-US%22%3EOnline%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issued%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1152273%22%20slang%3D%22en-US%22%3E%3CP%3EI%20want%20to%20have%20a%20couple%20of%20users%20which%20are%20not%20able%20to%20use%20any%20of%20the%20Office%20365%20online%20services%20(like%20Planner%2C%20SharePoint%2C%20OneDrive).%20Therefore%20I%20created%20a%20security%20group%20with%20the%20members%20and%20a%20standard%20Office%20365%20E3%20license%20and%20only%20Microsoft%20Teams%20as%20an%20application.%20But%20the%20user%20is%20still%20able%20to%20access%20all%20online%20services.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1152273%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Elicenses%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOnline%20Services%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Euser%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1153633%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issued%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1153633%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F517500%22%20target%3D%22_blank%22%3E%40Thomas_Steibl%3C%2FA%3E%2C%20the%20last%20time%20I%20checked%2C%20%3CEM%3Eaccess%3C%2FEM%3E%20to%20SharePoint%20is%20granted%20to%20synced%20users%20by%20default.%20No%20licence%20required.%20It%20is%20that%20certain%20functionality%20of%20SharePoint%20is%20deprecated%20for%20licensed%20users.%3CBR%20%2F%3EWhat%20you%20need%20is%20to%20explicitly%20block%20access%20to%20SharePoint%20for%20users.%20What%20has%20worked%20for%20me%20in%20the%20past%20is%3C%2FP%3E%3CP%3E1-%20make%20sure%20none%20of%20the%20sites%20have%20blanket%20access%20(eg%20access%20to%20Everyone%2C%20or%20Everyone%20except%20external%20user)%3C%2FP%3E%3CP%3E2-%20Create%20a%20security%20group%20with%20all%20the%20users%20who%20should%20have%20access%20and%20grant%20that%20group%20access%20appropriately%3C%2FP%3E%3CP%3ESame%20goes%20with%20ODFB%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1153721%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issued%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1153721%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F419534%22%20target%3D%22_blank%22%3E%40mrehmat%3C%2FA%3E%26nbsp%3Bokay%20thanks!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20why%20is%20it%20also%20possible%20to%20access%20planner%20for%20instance.%20Why%20is%20it%20even%20possible%20to%20select%20or%20deselect%20this%20application%20for%20users%20in%20the%20licensing%20process%20if%20it's%20available%20anyway%3F%3F%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1163678%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issued%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1163678%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F517500%22%20target%3D%22_blank%22%3E%40Thomas_Steibl%3C%2FA%3E%26nbsp%3BYou%20can%20block%20access%20for%20specific%20users%20with%20Azure%20AD%20Conditional%20Access.%20Regardless%20of%20their%20license%20status.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166012%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issued%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166012%22%20slang%3D%22en-US%22%3ECan%20you%20explain%20that%20to%20me%20a%20little%20further%3F%3CBR%20%2F%3ECurrently%20I%20don't%20see%20a%20chance%20to%20disable%20all%20online%20services%20besides%20Teams%3F!%20Since%20I%20can't%20select%20Teams%20individually%3F!%3CBR%20%2F%3EThanks%20in%20advance.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166051%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issued%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166051%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F517500%22%20target%3D%22_blank%22%3E%40Thomas_Steibl%3C%2FA%3E%26nbsp%3BSee%20attached%20screenshot.%20You%20can%20select%20all%20apps%20and%20then%20make%20exclusions%20if%20you%20want.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Foverview%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166633%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issuedlock%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166633%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F470541%22%20target%3D%22_blank%22%3E%40JanBakker330%3C%2FA%3E!%20I%20created%20a%20policy%20to%20block%20all%20access%20and%20included%20all%20cloud%20apps%20and%20excluded%20Teams.%20Unfortunately%20I%20can't%20access%20any%20resources%20anymore%20(office.com%20or%20Teams%20App)...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Annotation.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F170337iD03A594D70E2D1F5%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Annotation.png%22%20alt%3D%22Annotation.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166727%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issuedlock%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166727%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F517500%22%20target%3D%22_blank%22%3E%40Thomas_Steibl%3C%2FA%3E%26nbsp%3B%3CSPAN%3EUnfortunately%26nbsp%3Bthis%20cannot%20be%20done%20for%20the%20Teams%20app%2C%20because%20Teams%20is%20also%20triggered%20when%20you%20use%20the%20Office%20365%20(preview)%2C%20SharePoint%20and%20Exchange%20app.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JanBakker330_0-1581433256938.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F170348i3FBE1CEE554E003D%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22JanBakker330_0-1581433256938.png%22%20alt%3D%22JanBakker330_0-1581433256938.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166960%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issuedlock%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166960%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20a%20way%20to%20restrict%20Browser%20access%3F%20For%20instance%20-%20it's%20fine%20if%20the%20user%20is%20within%20a%20Teams%20group%20where%20they%20are%20using%20Planner%2C%20but%20the%20user%20should%20not%20be%20able%20to%20open%20tasks.office.com...%3C%2FP%3E%3CP%3EA%20user%20should%20be%20able%20to%20use%20the%20Teams%20client%20but%20not%20the%20Teams%20browser%20interface.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1168849%22%20slang%3D%22en-US%22%3ERe%3A%20Online%20Services%20available%20even%20if%20there%20are%20no%20Licenses%20issuedlock%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1168849%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F517500%22%20target%3D%22_blank%22%3E%40Thomas_Steibl%3C%2FA%3E%26nbsp%3BYes%2C%20you%20can%20also%20do%20this%20with%20conditional%20access.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20restrict%20browser%20access%20for%20the%20apps%20you've%20selected.%20Users%20can%20still%20use%20the%20Desktop%20%26amp%3B%20Mobile%20clients.%20In%20order%20to%20do%20that%2C%20you%20can%20select%20Browsers%20from%20the%20Client%20app%20section%20under%20Conditions.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBe%20careful%20of%20what%20users%20and%20apps%20you%20select.%20You%20can%20easily%20lock%20yourself%20out%20%3B)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JanBakker330_0-1581499946036.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F170814i93D5C1F3E5A1F7AB%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22JanBakker330_0-1581499946036.png%22%20alt%3D%22JanBakker330_0-1581499946036.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

I want to have a couple of users which are not able to use any of the Office 365 online services (like Planner, SharePoint, OneDrive). Therefore I created a security group with the members and a standard Office 365 E3 license and only Microsoft Teams as an application. But the user is still able to access all online services.

9 Replies
Highlighted

@Thomas_Steibl, the last time I checked, access to SharePoint is granted to synced users by default. No licence required. It is that certain functionality of SharePoint is deprecated for licensed users.
What you need is to explicitly block access to SharePoint for users. What has worked for me in the past is

1- make sure none of the sites have blanket access (eg access to Everyone, or Everyone except external user)

2- Create a security group with all the users who should have access and grant that group access appropriately

Same goes with ODFB

Highlighted

@mrehmat okay thanks!

 

But why is it also possible to access planner for instance. Why is it even possible to select or deselect this application for users in the licensing process if it's available anyway???

Highlighted

@Thomas_Steibl You can block access for specific users with Azure AD Conditional Access. Regardless of their license status.

Highlighted
Can you explain that to me a little further?
Currently I don't see a chance to disable all online services besides Teams?! Since I can't select Teams individually?!
Thanks in advance.
Highlighted

@Thomas_Steibl See attached screenshot. You can select all apps and then make exclusions if you want. 

 

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview 

Highlighted

Thanks @JanBakker330! I created a policy to block all access and included all cloud apps and excluded Teams. Unfortunately I can't access any resources anymore (office.com or Teams App)...

 

Annotation.png

Highlighted

@Thomas_Steibl Unfortunately this cannot be done for the Teams app, because Teams is also triggered when you use the Office 365 (preview), SharePoint and Exchange app. 

 

 

 

JanBakker330_0-1581433256938.png

 

 

Highlighted

Is there a way to restrict Browser access? For instance - it's fine if the user is within a Teams group where they are using Planner, but the user should not be able to open tasks.office.com...

A user should be able to use the Teams client but not the Teams browser interface.

Highlighted

@Thomas_Steibl Yes, you can also do this with conditional access. 

 

You can restrict browser access for the apps you've selected. Users can still use the Desktop & Mobile clients. In order to do that, you can select Browsers from the Client app section under Conditions. 

 

Be careful of what users and apps you select. You can easily lock yourself out ;) 

 

JanBakker330_0-1581499946036.png