question

jamiebrandwood avatar image
0 Votes"
jamiebrandwood asked ·

Conditional Access with Azure Registered App

Is there a way to restrict access to an Azure AD registered application based on IP address or location when the said application is using a client secret because of its use as a Windows Service for example. so no underlying user to pass credentials?


This would mean there is no username passed to Azure AD in order to evaluate against a conditional access policy?


Has anyone else seen this scenario or have a solution for it? is there even a solution?

azure-active-directory
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

amanpreetsingh-msft avatar image
1 Vote"
amanpreetsingh-msft answered ·

@jamiebrandwood Conditional access policy cannot be applied if you are requesting token under application context i.e., using client credentials.

There is an active feedback regarding this feature here: https://feedback.azure.com/forums/169401-azure-active-directory/suggestions/37867180-restricting-access-of-azure-service-principals-u. Please vote here as this is monitored by MS product team and based on the popularity of the idea features are added to Azure.


Please "Accept as answer" wherever the information provided helps you to help others in the community.

· 2 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks for the response, appreciate the confirmation that i'm at least not going crazy :-),

Is there anyway to restrict access by any means? if not with conditional access today? would MCAS maybe cover this requirement?

0 Votes 0 ·

@jamiebrandwood MCAS doesn't have this feature. The only option for location based restriction is Conditional Access, which unfortunately can't be applied to applications.


Please "Accept as answer" wherever the information provided helps you to help others in the community.

0 Votes 0 ·