Microsoft 365 Conditional Access Policy for External Guest Users | Configuration Guide

Configure Conditional Access Policy for Microsoft 365 Guest Users

Question

You have a Microsoft 365 subscription.

Your organization is frequently collaborating with external users from different companies.

You want to automatically target all guest users, new and old, with a conditional access policy and also assign them a license.

How should you configure this?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

Correct Answer: A

Create a dynamic group in Azure AD with an expression in the Rule syntax box that locates all active guest users and adds them to the group.

Then you scope the conditional access policy to the group containing the guest users.

Then you add the license to the group, which in turn assigns the license to all its members.

New
Conditional Access policy

Control user access based on Conditional
‘Access policy to bring signals together, to
make decisions, and enforce organizational
policies, Learn more

Assignments

Users and groups ©

Specific users included

Cloud apps or actions

No cloud apps, actions, or authentication
contexts selected

Control user access based on users and groups
assignment for all users, specific groups of
users, directory roles, or external guest users
Learn more

Include

O None
O aAllusers

© Select users and groups

Exclude

@ Allquest and external users

(1 Directory roles

( Users and groups

To know more about grouping guest users in dynamics groups, please refer to the link below:

The correct answer is A. Create a dynamic group in Azure Active Directory.

Explanation:

To automatically target all guest users, new and old, with a conditional access policy and assign them a license, you can create a dynamic group in Azure Active Directory. A dynamic group is a collection of users that share a common attribute. In this case, the attribute that you can use to create the group is the user's user type. The user type for guest users in Microsoft 365 is "Guest".

Here are the steps to create a dynamic group in Azure Active Directory:

  1. Sign in to the Azure portal with an account that has the appropriate permissions.

  2. In the left-hand menu, click on "Azure Active Directory".

  3. Click on "Groups" and then click on "New Group".

  4. In the "Group type" section, select "Dynamic".

  5. In the "Group membership rules" section, click on "Add dynamic query".

  6. In the "Edit dynamic query" window, select "User" as the object type.

  7. For the attribute, select "User type".

  8. For the operator, select "Equals".

  9. For the value, enter "Guest".

  10. Click on "Save".

  11. Give the group a name and a description.

  12. Click on "Create".

Once you have created the dynamic group, you can create a conditional access policy and assign it to the group. The policy will apply to all guest users who are members of the group.

Here are the steps to create a conditional access policy:

  1. In the Azure portal, click on "Security".

  2. Click on "Conditional Access".

  3. Click on "New policy".

  4. Give the policy a name.

  5. In the "Assignments" section, click on "Users and groups".

  6. Click on "Select users and groups".

  7. Search for the dynamic group that you created earlier and select it.

  8. Click on "Done".

  9. In the "Cloud apps or actions" section, select the Microsoft 365 apps that you want to apply the policy to.

  10. In the "Conditions" section, configure the conditions for the policy. For example, you can require multi-factor authentication for all guest users.

  11. In the "Access controls" section, configure the access controls for the policy. For example, you can block access or require approval for access.

  12. Click on "Enable policy".

Finally, you can assign a license to the dynamic group. This will ensure that all guest users who are members of the group have access to the appropriate Microsoft 365 features.

Here are the steps to assign a license to the dynamic group:

  1. In the Azure portal, click on "Azure Active Directory".

  2. Click on "Licenses".

  3. Click on "All products".

  4. Select the Microsoft 365 product that you want to assign a license for.

  5. Click on "Assignments".

  6. Click on "Add group assignment".

  7. Search for the dynamic group that you created earlier and select it.

  8. Configure the license settings as appropriate.

  9. Click on "Assign".

By following these steps, you can automatically target all guest users, new and old, with a conditional access policy and assign them a license.