logo

ZTCA Configuration: Restrict Azure management sign-ins to trusted IPs using Entra Conditional Access

ID: 92bfa8c2-536e-5386-b49e-11695869bd27

STIX ID: report--92bfa8c2-536e-5386-b49e-11695869bd27

Feed Name: ThreatLocker Blog

Date Published: 2026-06-15

Date Updated: 2026-06-16

...
...

This article is a step-by-step guide for configuring Microsoft Entra Conditional Access to restrict Azure management-plane sign-ins (portal, CLI, PowerShell, ARM API) to specified Named Location IP addresses, including creating the named location, building a policy targeting the Windows Azure Service Management API, validating in Report-only mode, excluding break-glass and automation accounts, and enabling enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.