Microsoft Look Book template deployment

%3CLINGO-SUB%20id%3D%22lingo-sub-2049125%22%20slang%3D%22en-US%22%3EMicrosoft%20Look%20Book%20template%20deployment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2049125%22%20slang%3D%22en-US%22%3E%3CP%3EI%20don't%20know%20if%20this%20is%20the%20right%20forum%20for%20this%20but%20I%20have%20just%20learned%20that%2C%20while%20the%20LookBook%20website%20indicates%20that%20only%20tenant%20admins%20are%20to%20be%20able%20to%20create%20sites%20using%20the%20templates%2C%20an%20E3%20licensed%20user%20with%20no%20admin%20roles%20just%20created%20his%20own%20Comm%20site%20without%20any%20issue%20or%20assistance%20and%20I%2C%20as%20the%20SharePoint%20and%20TEAMS%20administrator%20had%20no%20idea%20he%20did%20so.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20company%20has%20strict%20rules%20about%20who%20can%20create%20along%20with%20naming%20conventions%2C%20etc.%20to%20follow%20when%20creating%20and%20he%20was%20able%20to%20bypass%20ALL%20of%20it.%20I'm%20not%20faulting%20the%20user%2C%20I%20am%20faulting%20Microsoft's%20verbiage%20and%2For%20security.%20Either%20the%20website%20is%20erroneous%20when%20it%20says%20only%20admins%20can%20create%2Fuse%20the%20templated%20or%20there%20is%20a%20security%2Fmanagement%20breach%20going%20on%20for%20this.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20VERY%20concerned%20at%20what%20this%20means%20for%20our%20company%3A%20it%20will%20be%20Pandora's%20Box%20is%20a%20blink%20of%20an%20eye.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%2C%20would%20someone%20please%20explain%20what%20is%20going%20on%20and%20how%20I%20can%20stop%20this%20from%20being%20something%20anyone%20in%20my%20tenant%20can%20do%3F%26nbsp%3B%20QUICK!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2049125%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ELook%20Book%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

I don't know if this is the right forum for this but I have just learned that, while the LookBook website indicates that only tenant admins are to be able to create sites using the templates, an E3 licensed user with no admin roles just created his own Comm site without any issue or assistance and I, as the SharePoint and TEAMS administrator had no idea he did so. 

 

Our company has strict rules about who can create along with naming conventions, etc. to follow when creating and he was able to bypass ALL of it. I'm not faulting the user, I am faulting Microsoft's verbiage and/or security. Either the website is erroneous when it says only admins can create/use the templated or there is a security/management breach going on for this. 

 

I am VERY concerned at what this means for our company: it will be Pandora's Box is a blink of an eye.

 

Please, would someone please explain what is going on and how I can stop this from being something anyone in my tenant can do?  QUICK!

1 Reply

@Lisa Stebbins Sounds like when you or another tenant admin used the Lookbook previously, you consented the application "on behalf of the organization". What this means is essentially a Tenant Admin has approved this application for use and the permissions required by this application. I have attached the image of the check box you checked.

I do not think you meant to click this checkbox. When you provision using a tenant admin account, you do not need to select this box. As a result, the other users in your environment can now provision through the lookbook because you provided the consent. 

What you will need to do is....

1. Go to the Azure Portal to your Azure Active Directory settings
2. Go to Enterprise Applications
3. Locate SharePointPnP.ProvisioningApp.Tenant
4. Select Properties on the left
5. Delete this application

The next time you or a tenant admin use the Lookbook, do not consent on-behalf of your organization.