Sunday, May 24, 2020

Self Service Password reset (SSPR) in Azure

Self service password reset is a Azure Active Directory feature which enabled end user to reset their password by them self without contacting IT support.

Platform

Azure

Affected platform

Azure
Office 365


License requirement


Implementation roles

Global admin

Enabled Self Service Password Reset



Create dynamic membership groups


Rules can be used to determine group membership based on user or devices attributes. Basically it is a security group and the members inside the security group keep coming in  or going out based on user's device's properties.

Find all properties and operands that can be used in the rule at below article.


How to create membership group
1. Go to Azure Active Directory
2. Click on Groups --> New group and select membership type as dynamic user



















3. Add membership rule, In this case get all users from country INDIA








4. Click on validate tab to check the rule


5. Add users who country set as INDIA

6. Verification is success








7. User added in the group



Thursday, May 21, 2020

Layers of access in SharePoint Online

Office 365 SharePoint Online is providing multiple layer access to the customers.  Many of us spent lot of effort to protect the content and grant the correct access to the content that resided in SharePoint.

There are multiple layers of access is available in SharePoint Online. Look at all layers in below image.

SPO layered security

e,g scenario for above image

Allow external users with signing-in using their account. Site owner can decide upon content access to external. If need restricted access to a site then SPO Admin can restrict specific site from externals.




1.