Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Admin users are able to register third party software tokens due to SSPR authorization policy. #817

Closed
joibarr opened this issue May 15, 2024 · 3 comments

Comments

@joibarr
Copy link

joibarr commented May 15, 2024

Specifications:

  • Only impacting admin users
  • Combined registration migration is completed.

This document needs to clarify that even if the third party software token policy is disabled in the new authentication methods portal, because the SSPR Administrator policy enable by default all the methods for the admin users, these admin users are able to register third party software token apps that can be used to complete SSPR.

I was able to register a Google Authenticator even though the policy is disabled.


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

@PesalaPavan
Copy link
Contributor

@joibarr
Thanks for your feedback! We will investigate and update as appropriate.

@PesalaPavan PesalaPavan assigned Justinha and unassigned PesalaPavan May 17, 2024
@PesalaPavan PesalaPavan added assigned-to-author Issue assigned to author and removed cxp labels May 17, 2024
@PesalaPavan
Copy link
Contributor

@joibarr
Thanks for your feedback! I've assigned this issue to the author who will investigate and update as appropriate.

@Justinha
Copy link
Contributor

Justinha commented Jun 3, 2024

@joibarr sorry for delay and thanks for the suggestion. I added this to the topic. #please-close

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants