{"id":237,"date":"2024-06-14T23:50:43","date_gmt":"2024-06-14T21:50:43","guid":{"rendered":"http:\/\/deepdef.quaglia.fr\/?p=237"},"modified":"2024-06-14T23:58:48","modified_gmt":"2024-06-14T21:58:48","slug":"maitriser-et-limiter-les-postes-des-prestataires","status":"publish","type":"post","link":"https:\/\/deepdef.quaglia.fr\/index.php\/2024\/06\/14\/maitriser-et-limiter-les-postes-des-prestataires\/","title":{"rendered":"Ma\u00eetriser et limiter les postes des prestataires"},"content":{"rendered":"<div class=\"wpb-content-wrapper\">[vc_row][vc_column][vc_column_text][\/vc_column_text][vc_column_text css=&#8221;&#8221;]\r\n<div class=\"OFA52E\">\r\n<div class=\"cD_92h UitnHM\" tabindex=\"-1\" data-hook=\"post-title\">\r\n<h1 class=\"UbhFJ7 nkqC0Q blog-post-title-font blog-post-title-color blog-text-color post-title blog-hover-container-element-color FG3qXk blog-post-page-title-font\" data-hook=\"post-title\"><span class=\"post-title__text blog-post-title-font blog-post-title-color\"><span class=\"blog-post-title-font blog-post-title-color\">Comment ma\u00eetriser et limiter les postes des prestataires avec Azure AD et l\u2019acc\u00e8s conditionnel &#8211; REX<\/span><\/span><\/h1>\r\n<\/div>\r\n<\/div>\r\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text css=&#8221;&#8221;]\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-1ebsm\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Retour d\u2019exp\u00e9rience d\u2019un projet r\u00e9alis\u00e9 pour un grand compte bas\u00e9 en r\u00e9gion Occitanie, nomm\u00e9e par la suite l\u2019<strong>Organisation<\/strong>. <\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block1\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-am7po\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"am7po\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/642864_00b82692cb0a47808f2ec9e6227b3f57~mv2.png\/v1\/fill\/w_720,h_480,al_c,lg_1,q_85,enc_auto\/642864_00b82692cb0a47808f2ec9e6227b3f57~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/642864_00b82692cb0a47808f2ec9e6227b3f57~mv2.png\/v1\/fill\/w_720,h_480,al_c,lg_1,q_85\/642864_00b82692cb0a47808f2ec9e6227b3f57~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block2\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-c2vgh\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block3\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-4jgo0\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">Contexte<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block4\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-fgqru\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">A l\u2019instar de nombreuses entreprises, l\u2019<strong>Organisation<\/strong> en question ne fournit plus de postes de travail aux prestataires intervenant sur son SI (infog\u00e9rant, prestataires ponctuels, prestataires m\u00e9tiers\u2026). Chaque prestataire utilise un poste de travail multi-clients contr\u00f4l\u00e9 par sa propre soci\u00e9t\u00e9, ne permettant donc pas le d\u00e9ploiement du master de l\u2019<strong>Organisation<\/strong> sur ces postes.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block5\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-8o20u\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block6\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-d04em\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">De plus, l\u2019<strong>Organisation<\/strong>, dans une d\u00e9marche de bascule vers le cloud, publie au travers d\u2019Azure AD les applications et services utilis\u00e9s par les prestataires. Elle ne souhaite plus utiliser de solutions VPN pour contr\u00f4ler l\u2019acc\u00e8s \u00e0 ces ressources.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block7\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-fccq9\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block8\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-d399p\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Dans un premier temps, l\u2019<strong>Organisation<\/strong> a utilis\u00e9 l\u2019acc\u00e8s conditionnel d\u2019Azure combin\u00e9 \u00e0 du MFA pour prot\u00e9ger l\u2019acc\u00e8s aux ressources. Mais tr\u00e8s rapidement, il est apparu que les prestataires utilisaient aussi bien leurs ordinateurs personnels, professionnels ou leurs smartphones pour y acc\u00e9der.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block9\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-9evn\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block10\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-7ogpt\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">\u00a0<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block11\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-fnmtr\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">Contraintes<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block12\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-ci1dn\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">L\u2019<strong>Organisation<\/strong> souhaitait trouver une solution for\u00e7ant les prestataires \u00e0 utiliser un unique poste de travail professionnel, sans surco\u00fbt et sans surcharge de travail pour les \u00e9quipes internes en termes d\u2019exploitation.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block13\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-koso\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block14\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-2ob78\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">\u00a0<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block15\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-fa03o\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">Difficult\u00e9s<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block16\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-eia9b\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">La principale difficult\u00e9 de ce projet r\u00e9side dans l\u2019h\u00e9t\u00e9rog\u00e9n\u00e9it\u00e9 des postes de travail des diff\u00e9rents prestataires. Certains postes sont dans un domaine AD, d\u2019autres sont enr\u00f4l\u00e9s dans un MDM ou d\u2019autres encore sont en Azure AD join ou hybrid Azure AD join.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block17\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-1dk6\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block18\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-bs82\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">\u00a0<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block19\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-43ibe\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">Solutions \u00e9tudi\u00e9es<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block20\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-b8emf\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Plusieurs solutions ont \u00e9t\u00e9 \u00e9tudi\u00e9es, sans pour autant avoir \u00e9t\u00e9 retenues :<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block21\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<ul class=\"XXyNO LUlav\">\r\n<li class=\"dINAa\" dir=\"auto\">\r\n<p id=\"viewer-b7aa1\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"\"><span class=\"MuheC\">Le contr\u00f4le des acc\u00e8s aux applications au travers de MCAS (CASB de Microsoft) coupl\u00e9 avec un certificat utilisateur. Les contraintes d\u2019exploitation ont repr\u00e9sent\u00e9 un frein.<\/span><\/p>\r\n<\/li>\r\n<li class=\"dINAa\" dir=\"auto\">\r\n<p id=\"viewer-an4gd\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"\"><span class=\"MuheC\">Le management des terminaux avec l\u2019Intune de l\u2019<strong>Organisation<\/strong>. La solution n\u2019est pas fonctionnelle pour les postes d\u00e9j\u00e0 manag\u00e9s par un MDM.<\/span><\/p>\r\n<\/li>\r\n<li class=\"dINAa\" dir=\"auto\">\r\n<p id=\"viewer-eeejn\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"\"><span class=\"MuheC\">L\u2019utilisation d\u2019Azure Virtual Desktop, qui est la solution qui r\u00e9pond le mieux \u00e0 ce besoin d\u2019un point de vue s\u00e9curit\u00e9 et fonctionnel. Cependant, la solution n\u00e9cessite un vrai projet d\u2019int\u00e9gration et repr\u00e9sente un co\u00fbt \u00e0 l\u2019usage.<\/span><\/p>\r\n<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div data-hook=\"rcv-block22\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-1opco\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block23\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-edgh1\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">\u00a0<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block24\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h3 id=\"viewer-c39mi\" class=\"n0jl5 -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">Solution mise en \u0153uvre : Azure AD Registered + acc\u00e8s conditionnel<\/span><\/h3>\r\n<\/div>\r\n<div data-hook=\"rcv-block25\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-3pirn\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">La solution propos\u00e9e par <strong>Deepdef<\/strong> et s\u00e9lectionn\u00e9e par l\u2019<strong>Organisation<\/strong>, \u00ab Azure AD Registered + Conditional Access \u00bb, consiste \u00e0 faire enregistrer les postes de travail des prestataires sur l\u2019Azure AD de l\u2019<strong>Organisation<\/strong> et \u00e0 r\u00e9aliser un contr\u00f4le d\u2019acc\u00e8s en se basant sur la notion d\u2019\u00ab Azure AD Registered \u00bb.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block26\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-5ma0b\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block27\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-8vg12\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Ce scenario se base sur une fonctionnalit\u00e9 encore en preview du Conditional Access, Device state. Cette solution a \u00e9t\u00e9 choisie car elle r\u00e9pond aux deux pr\u00e9requis de l\u2019<strong>Organisation<\/strong>, \u00e0 savoir qu\u2019elle n\u2019entraine aucun co\u00fbt de licences suppl\u00e9mentaire, ni d\u2019efforts d\u2019exploitation de l\u2019\u00e9quipe interne, et se r\u00e9v\u00e8le simple \u00e0 mettre en \u0153uvre.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block28\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-b8guc\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block29\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<h6 id=\"viewer-a57g9\" class=\"N3t7u -oCyc LUlav d-O73\" dir=\"auto\"><span class=\"J6PEJ\">Mise en \u0153uvre<\/span><\/h6>\r\n<\/div>\r\n<div data-hook=\"rcv-block30\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-bhifr\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">La r\u00e8gle d\u2019acc\u00e8s conditionnel s\u2019appuie sur le filtrage des devices enregistr\u00e9s, en cons\u00e9quence tout acc\u00e8s aux applications est refus\u00e9 sauf pour les devices enregistr\u00e9s dans Azure AD :<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block31\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-eg267\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"eg267\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/171724_fef7e8fed8c7434ea467df64fdc9189d~mv2.png\/v1\/fill\/w_740,h_123,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/171724_fef7e8fed8c7434ea467df64fdc9189d~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/171724_fef7e8fed8c7434ea467df64fdc9189d~mv2.png\/v1\/fill\/w_1323,h_220,al_c,lg_1,q_85\/171724_fef7e8fed8c7434ea467df64fdc9189d~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block32\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-9s59n\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block33\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-6t86a\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Une limite du nombre de devices enregistr\u00e9s par utilisateur est impos\u00e9e, ici un device :<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block34\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-cmq8h\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"cmq8h\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/171724_6c8d43f8db664d79b07cfda7a29d376a~mv2.png\/v1\/fill\/w_740,h_156,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/171724_6c8d43f8db664d79b07cfda7a29d376a~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/171724_6c8d43f8db664d79b07cfda7a29d376a~mv2.png\/v1\/fill\/w_1096,h_232,al_c,lg_1,q_85\/171724_6c8d43f8db664d79b07cfda7a29d376a~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block35\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-24afe\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block36\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-a1tts\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">L\u2019enregistrement du poste de travail est r\u00e9alis\u00e9 par l\u2019utilisateur lui-m\u00eame. La manipulation est simple et ne n\u00e9cessite pas de privil\u00e8ges \u00e9lev\u00e9s.<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block37\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-1t0eq\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block38\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-4eumu\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Cette solution a l\u2019avantage de fonctionner avec un grand nombre de modes de gestion des postes de travail des organisations prestataires :<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block39\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<ul class=\"XXyNO LUlav\">\r\n<li class=\"dINAa\" dir=\"auto\">\r\n<p id=\"viewer-9gbhp\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"\"><span class=\"MuheC\">Depuis un poste de travail inscrit dans un domaine AD :<\/span><\/p>\r\n<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div data-hook=\"rcv-block40\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-b30ni\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block41\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-9k619\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"9k619\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/171724_8a311ea838734216a452155673ca4911~mv2.png\/v1\/fill\/w_740,h_329,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/171724_8a311ea838734216a452155673ca4911~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/171724_8a311ea838734216a452155673ca4911~mv2.png\/v1\/fill\/w_945,h_420,al_c,q_90\/171724_8a311ea838734216a452155673ca4911~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block42\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-nbpl\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block43\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<ul class=\"XXyNO LUlav\">\r\n<li class=\"dINAa\" dir=\"auto\">\r\n<p id=\"viewer-f8be8\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"\"><span class=\"MuheC\">Depuis un poste de travail d\u00e9j\u00e0 enr\u00f4l\u00e9 dans un Intune :<\/span><\/p>\r\n<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div data-hook=\"rcv-block44\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-akdm2\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"akdm2\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/171724_f1a78b1192eb4b59add465539342dc79~mv2.png\/v1\/fill\/w_740,h_212,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/171724_f1a78b1192eb4b59add465539342dc79~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/171724_f1a78b1192eb4b59add465539342dc79~mv2.png\/v1\/fill\/w_1134,h_325,al_c,lg_1,q_90\/171724_f1a78b1192eb4b59add465539342dc79~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block45\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-fb7po\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block46\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<ul class=\"XXyNO LUlav\">\r\n<li class=\"dINAa\" dir=\"auto\">\r\n<p id=\"viewer-9qbn6\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"\"><span class=\"MuheC\">Depuis un poste de travail Azure AD join :<\/span><\/p>\r\n<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div data-hook=\"rcv-block47\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-2jpu2\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"2jpu2\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/171724_f869095fc44e48688137c4752f0a4fa8~mv2.png\/v1\/fill\/w_740,h_283,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/171724_f869095fc44e48688137c4752f0a4fa8~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/171724_f869095fc44e48688137c4752f0a4fa8~mv2.png\/v1\/fill\/w_1134,h_434,al_c,lg_1,q_90\/171724_f869095fc44e48688137c4752f0a4fa8~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block48\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-ce9eq\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block49\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-duosl\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Lorsque l\u2019utilisateur tente d\u2019acc\u00e9der \u00e0 une ressource depuis un poste non enregistr\u00e9, l\u2019acc\u00e8s est bloqu\u00e9 :<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block50\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-fvu4k\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"fvu4k\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/171724_7c348e307c534c03a3fe157704cec44d~mv2.png\/v1\/fill\/w_740,h_461,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/171724_7c348e307c534c03a3fe157704cec44d~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/171724_7c348e307c534c03a3fe157704cec44d~mv2.png\/v1\/fill\/w_945,h_589,al_c,q_90\/171724_7c348e307c534c03a3fe157704cec44d~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block51\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-asf0s\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block52\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-3m9r3\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">Afin de s\u2019assurer que l\u2019utilisateur enregistre et utilise bien un poste de travail de sa soci\u00e9t\u00e9, il est possible de compl\u00e9ter la r\u00e8gle d\u2019acc\u00e8s conditionnel avec l\u2019identit\u00e9 du device :<\/span><\/p>\r\n<\/div>\r\n<div data-hook=\"rcv-block53\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-6hvq0\" class=\"Hq2Ig\">\r\n<div class=\"yyLrD gD2rB\">\r\n<figure class=\"_2slDA\" tabindex=\"0\" role=\"button\" data-hook=\"imageViewer\">\r\n<div id=\"6hvq0\" class=\"wzu16 VohSv _-0N4B\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/171724_eaf7b69942384398ad7d97862402e022~mv2.png\/v1\/fill\/w_740,h_273,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/171724_eaf7b69942384398ad7d97862402e022~mv2.png\" alt=\"\" data-pin-url=\"https:\/\/www.deepdef.com\/post\/ma\u00eetriser-limiter-postes-prestataires-azuread-acc\u00e8sconditionnel\" data-pin-media=\"https:\/\/static.wixstatic.com\/media\/171724_eaf7b69942384398ad7d97862402e022~mv2.png\/v1\/fill\/w_1134,h_419,al_c,lg_1,q_90\/171724_eaf7b69942384398ad7d97862402e022~mv2.png\" data-load-done=\"\" \/><\/div>\r\n<\/figure>\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block54\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<div id=\"viewer-687it\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">\u00a0<\/span><\/div>\r\n<\/div>\r\n<div data-hook=\"rcv-block55\">\u00a0<\/div>\r\n<div data-breakout=\"normal\">\r\n<p id=\"viewer-4im4\" class=\"Yxme4 _7TwO0 LUlav d-O73\" dir=\"auto\"><span class=\"MuheC\">L\u2019alimentation de la liste de device ID peut \u00eatre script\u00e9e et se baser sur un fichier qui sera renseign\u00e9 par la soci\u00e9t\u00e9 prestataire elle-m\u00eame et ainsi n\u2019entrainer aucune charge de travail suppl\u00e9mentaire pour l\u2019<strong>Organisation<\/strong>.<\/span><\/p>\r\n<\/div>\r\n[\/vc_column_text][\/vc_column][\/vc_row]<\/div>","protected":false},"excerpt":{"rendered":"[vc_row][vc_column][vc_column_text][\/vc_column_text][vc_column_text css=&#8221;&#8221;] Comment ma\u00eetriser et limiter les postes des prestataires avec Azure AD et l\u2019acc\u00e8s conditionnel &#8211; REX [\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text css=&#8221;&#8221;] Retour d\u2019exp\u00e9rience d\u2019un projet r\u00e9alis\u00e9 pour un grand compte bas\u00e9 en r\u00e9gion Occitanie, nomm\u00e9e par la suite l\u2019Organisation. \u00a0 \u00a0 \u00a0 \u00a0 Contexte \u00a0 A l\u2019instar de nombreuses entreprises, l\u2019Organisation en question ne fournit plus [&#8230;]\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"sfsi_plus_gutenberg_text_before_share":"","sfsi_plus_gutenberg_show_text_before_share":"","sfsi_plus_gutenberg_icon_type":"","sfsi_plus_gutenberg_icon_alignemt":"","sfsi_plus_gutenburg_max_per_row":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-237","post","type-post","status-publish","format-standard","hentry","category-non-classe"],"_links":{"self":[{"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/posts\/237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/comments?post=237"}],"version-history":[{"count":3,"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/posts\/237\/revisions"}],"predecessor-version":[{"id":240,"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/posts\/237\/revisions\/240"}],"wp:attachment":[{"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/media?parent=237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/categories?post=237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepdef.quaglia.fr\/index.php\/wp-json\/wp\/v2\/tags?post=237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}