The settingWhat we hold this to
CreativeTechs minimum
A CA policy in state ENABLED targeting the Microsoft Azure Management cloud app, All users excluding directory roles and break-glass, grant = Block.
Benchmark position
No published numeric benchmark. Huntress ships 'Restrict Azure Portal Management' as a managed CA template, High · Foundational. Maester MT.1008 tests for the policy's existence and currently PASSES on the CreativeTechs tenant.
Where the switch is
Entra admin centre → Protection → Conditional Access → Policies → New policy → Target resources → Cloud apps → Microsoft Azure Management.
How to verify
Graph: /identity/conditionalAccess/policies → conditions.applications.includeApplications contains '797f4846-ba00-4fd7-ba43-dac1f8f63013'
- Why it matters
- A standard user has no business in the Entra portal, and portal access is where directory reconnaissance happens after the first account falls.
- How we check
- Huntress managed CA template 'Restrict Azure Portal Management' (High · Foundational). Maester MT.1008 — currently Passed on our own tenant.
- Fix — M365
- CA policy targeting the Microsoft Azure Management app → block for everyone outside directory roles.
- Fix — Google
- Admin console access is already role-gated.
- User notices
- None for normal users — most have never opened it.
- Expected pushback
- None.
