Azure AD prevent login user without liense

Mönnikes, Marc 1 Reputation point
2020-01-29T10:00:42.513+00:00

Hello,

users are synchronized with local AD for Exchange hybrid GAL.
We hae users without Office365 or other Cloud license.

this users can login to cloud websites like www.office.com (only myapps are visible).

But we want to prevent that users without license can login to cloud websites.

Only users with active office365 license should be possible to login.

Can we configure this?

thank you

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,473 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. AmanpreetSingh-MSFT 56,306 Reputation points
    2020-01-29T10:19:53.397+00:00

    @Mönnikes, Marc Unfortunately, there is no direct way to do this. However, in order to prevent unlicensed users form login to cloud apps, you can use Conditional Access policy. If you are using Group Based Licensing (GBL), you can add the group to Conditional Access policy with rule like All Users except member of the group that you are using for GBL should be blocked for All Cloud Apps.

    If you are not using GBL, you may consider using it, as assigning licenses at the individual user level, can make large-scale management difficult. This will help you achieving the requirement that you have described.

    Note: Conditional Access is a premium feature and would require Azure AD Premium P1/P2 license.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept as answer" wherever the information provided helps you to help others in the community.


  2. Vasil Michev 95,341 Reputation points MVP
    2020-01-29T16:39:51.25+00:00

    Why don't you simply block those users via the corresponding controls in the portal (or the BlockCredential parameter in PowerShell)? It's easy enough to list them...

    0 comments No comments

  3. Mönnikes, Marc 1 Reputation point
    2020-01-30T13:36:01.113+00:00

    Hello michev,

    thank you for your answer.
    Which controls do you mean in the portal?

    The "sign in blocked" was overwritten after next Azure AD synchronisation, when i remember correctly.

    Regards