How to create conditional access policy in Office 365 to block access for Microsoft 365 apps for Business applications from non-domain joined devices and allow only email and SharePoint.

To allow and block microsoft365 applications we would use conditional access policy for endpoints.
 

 

·        Login to https://endpoint.microsoft.com/

·        Note: Access to 365endpoint console available from https://admin.microsoft.com/ too

·        Go to Conditional Access

·        Create a new policy.

o   Name the policy.

o   Assignments section: select users or groups the policy should apply

o  


o   Cloud apps or actions

§  section, click on the "+ Include" button to add an app.

§  Select apps.

§  Search for Microsoft 365 apps for Business

o   If you want to exclude email and SharePoint from blocking, you can exclude following.

§   


o   Conditions

§  Select Device: platform you want to apply policy.

·        Exclude: If needed Android IOS and Windows Phone

§  Locations: If needed

§  Client apps: If needed

§  Filter for device: If needed

o   Access control

§  Select: Required Hybrid azure AD joined device

§  For multiple controls: required all the selected controls.

o   Enable Policy: on

·        Click Save

You will get notification: “Successfully created 'Block Microsoft 365 apps for Business on non-domain joined computers.'” ·

Comments

Popular posts from this blog

How to check when Sharepoint List was created using PowerShell.

How to connect SharePoint online with SharePoint designer 2013

How to Send email from Scanner or Custom Applications using Microsoft365 SMTP or MX record