MS Entra Tenant Restrictions: Personal Journey with Securing External Access
Introduction
What is MS Entra Tenant Restrictions?
The Core Problem
How Many Ways Can Tenant Restrictions Be Implemented?
1. Tenant Restrictions V1
2. Tenant Restrictions V2
3. Universal Tenant Restrictions
Tenant Restrictions V1 vs V2: A Detailed Comparison
V1 Architecture and Limitations
V2 Enhanced Architecture
Practical Implementation: Blocking External SaaS While Allowing Gallery Apps
Scenario Overview
Implementation Strategy
Step 1: Configure Default Tenant Restrictions V2
Step 2: Create Partner Policies for Gallery Apps
Step 3: Configure Client-side Enforcement
Real-world Implementation Flow
Data Plane Protection: Advanced Security Features
Anonymous Access Protection
Token Infiltration Prevention
Monitoring and Compliance
Sign-in Logs Analysis
Audit Events
Best Practices from My Experience
1. Gradual Rollout Strategy
2. Exception Management
3. User Education
Troubleshooting Common Issues
1. Authentication Failures
2. Application Access Denied
3. Anonymous Access Issues
Looking Forward: Future Considerations
Integration with Zero Trust
Emerging Threats
Conclusion
PreviousSAML vs JWT Tokens: A Developer's Journey Through Token TechnologiesNextUnderstanding Delegated vs Application Permissions in MS Graph API
Last updated