How to block users from logging in to their Microsoft Personal Accounts using Header Insertion

How to block users from logging in to their Microsoft Personal Accounts using Header Insertion

17013
Created On 04/04/23 15:07 PM - Last Modified 01/23/24 22:23 PM


Objective


To block users from logging in to their MS personal accounts such as Outlook.com or OneDrive using use header insertion feature by applying the custom header to the "login.live.com" domain.
 


Environment


  • Palo Alto Firewalls
  • Supported PAN-OS
  • URL Filtering Profile


Procedure


  1. Under our URL Filtering profile , create a new header insertion entry:
    • Name: Give a name of this new entry, in our test it would be "Block-MS-Personal-Accounts"
    • Under type, choose "custom"
    • Under Domains, add this wildcard domain "login.live.com"
    • Under Headers, add the header "sec-Restrict-Tenant-Access-Policy" with the value "restrict-msa".
    • Click Ok
image.png
  1. Attach the URL Filtering to the desired security policy.
  2. When the user will tries to authenticate, after providing his credential, the following error message is displayed.
image.png


 
 


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1E2CAI&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language