Legacy Auth with Service Principal

Roman Mazzella 1 Reputation point
2021-07-20T13:24:15.653+00:00

Setting up the conditional access rule to block legacy oauth and noticed my cloud backup provider is using it as a service principal. How do I exclude this from being blocked or is it automatically excluded?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,369 questions
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,351 Reputation points Microsoft Employee
    2021-07-20T21:21:37.337+00:00

    @Roman Mazzella
    Thank you for your post!

    Based off our What is Conditional Access documentation, your service principal should be excluded from your conditional access policy, because CA policies are if-then statements, if a user wants to access a resource. Additionally, within the Portal it only allows you to exclude Users, Groups, or specific Directory roles from your policy, and not service principals.

    116431-image.png

    Additional Links:
    Service principal object
    Client apps
    Block legacy authentication

    I hope this helps! If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.