Forum Discussion
Bernard_Semplicita
Dec 05, 2021Copper Contributor
Condititional Access blocks access to AAD Management portal
Hi, I’m trying to build CA policy with a block all, unless policy. Therefore I have setup a block all rule, and with an exception of the ‘Microsoft Azure Management’ cloud application. The second ...
Bernard_Semplicita
Copper Contributor
What i am trying to achieve with CA is to block all access, unless an application/resource is specifically is allowed. To allow access to the azure portal if have created the described rules. But allthough 'AAD management' is part of the 'Windows Azure Service Management API' resource, it is blocked by CA. My question is why. Based on the CA rules, i should be able te access both.
Dec 05, 2021
Hi, I'm also finding it kind of difficult to understand your config (or at least the description). When you create policies using 'Microsoft Azure Management' app these are included.
Azure portal
Azure Resource Manager provider
Classic Service Management APIs
*Azure PowerShell
Visual Studio subscriptions administrator portal
Azure DevOps
Azure Data Factory portal
Azure Event Hubs
Azure Service Bus
Azure SQL Database
SQL Managed Instance
Azure Synapse
*Microsoft Azure Management application applies to Azure PowerShell, which calls the Azure Resource Manager API. It does not apply to Azure AD PowerShell, which calls Microsoft Graph.
Azure portal
Azure Resource Manager provider
Classic Service Management APIs
*Azure PowerShell
Visual Studio subscriptions administrator portal
Azure DevOps
Azure Data Factory portal
Azure Event Hubs
Azure Service Bus
Azure SQL Database
SQL Managed Instance
Azure Synapse
*Microsoft Azure Management application applies to Azure PowerShell, which calls the Azure Resource Manager API. It does not apply to Azure AD PowerShell, which calls Microsoft Graph.