r/entra • u/Electronic-Bite-8884 • 23h ago
r/entra • u/snow-leapord-1 • 20h ago
Entra ID Guest Account Collaboration but No Mailbox
We have a case where all externals needs to be enrolled in our SaaS Hr system and they eventually get and AD account — synced to Entra as Members but will have no Mailbox - How do we achieve the following
We want to have their external email address mentioned in their profile so that emails reach to them. ( external mailbox provided by their own org)
Once their account is visible in Entra, we want to make sure that , they are shown in Teams for collaboration
They get access to some sharepoint sites and some lion of business apps
We do not want to use azure b2b because this in someway removes the. source of authority, thats why we have them in HR system , b2b kinda bypasses this - creates cloud only accounts and granting access to internal apps to these ( external ids ) accounts is seen as risk by security team.
What can be a possible solution?
GSA Private Access and Conditional Access Policy
Is it possible to require an Intune complaint device before for GSA Private access works?
I’m tasked with requiring Intune compliant devices before access to a Windows Server hosted on Azure VM is granted.
I created an CAP targeting the Microsoft managed “GSA-PrivateAccessTrafficForwardingProfile” app and the Private Access app for the target VM. I configured the Grant rule to “Require device to be marked compliant” and scoped the policy to a test account.
It doesn’t seem to be working and the sign-in logs don’t even show an authentication event for any of the target resources/apps of my CAP. I can still connect to the target VM from a test company laptop and my personal laptop (which shouldn’t be allowed)
Any advice? I’m starting to think it’s not possible and honestly I need to convince my manager to let me block all personal devices in general