{"id":2253,"date":"2021-05-19T08:50:05","date_gmt":"2021-05-19T08:50:05","guid":{"rendered":"https:\/\/modern-workplace.uk\/?p=2253"},"modified":"2021-05-19T08:56:50","modified_gmt":"2021-05-19T08:56:50","slug":"teams-virtual-sbc-closing-azure-network-ports-warnings-for-azureloadbalancer-and-virtualnetwork-2-2-2-2-3-2","status":"publish","type":"post","link":"https:\/\/modern-workplace.uk\/?p=2253","title":{"rendered":"Teams &#8211; Blocking Logins to Personal Accounts &#8211; Blocking Logins to Accounts in Unapproved Tenants"},"content":{"rendered":"\n<p class=\"has-normal-font-size\">With a recent update, Microsoft has added the capability to use in the Teams app (desktop, mobile and web) both your work account and your personal account (meant to be used to communicate with family and friends).<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-9.png\"><img loading=\"lazy\" decoding=\"async\" width=\"591\" height=\"269\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-9.png\" alt=\"\" class=\"wp-image-2265\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-9.png 591w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-9-300x137.png 300w\" sizes=\"auto, (max-width: 591px) 100vw, 591px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>Whatever is your reaction to this decision there is a practical issue for some companies with strict security requirements. From their point of view access to Teams personal accounts, on the same mobile or desktop used for corporate connection, could impact the security policies.<\/p>\n\n\n\n<p class=\"has-normal-font-size\">The next logical step is to disable the access to Teams personal accounts on the devices used for work. A similar issue (and solution) can be used to limit access to unapproved Office 365 tenants. Surprisingly, the above control is not something that you can do using a Teams policy.<\/p>\n\n\n\n<p class=\"has-large-font-size\">Teams Free account<\/p>\n\n\n\n<p class=\"has-normal-font-size\">Creating a free account in Teams requires just a few steps (see images below) and you can use an existing email address<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-1.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-1.png\" alt=\"\" class=\"wp-image-2255\" width=\"450\" height=\"159\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-1.png 602w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-1-300x106.png 300w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><\/a><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-2.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-2.png\" alt=\"\" class=\"wp-image-2256\" width=\"451\" height=\"458\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-2.png 416w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-2-296x300.png 296w\" sizes=\"auto, (max-width: 451px) 100vw, 451px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>The new account will be shown as &#8220;personal<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-3.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-3.png\" alt=\"\" class=\"wp-image-2257\" width=\"461\" height=\"176\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-3.png 602w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-3-300x115.png 300w\" sizes=\"auto, (max-width: 461px) 100vw, 461px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-large-font-size\">Desktop App Experience: <\/p>\n\n\n\n<p>Now, inside the desktop app, you are able to add your personal account<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-6.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-6.png\" alt=\"\" class=\"wp-image-2260\" width=\"293\" height=\"135\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-6.png 581w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-6-300x138.png 300w\" sizes=\"auto, (max-width: 293px) 100vw, 293px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-normal-font-size\">After that, it is easy to switch between the two accounts<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-5.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-5.png\" alt=\"\" class=\"wp-image-2259\" width=\"292\" height=\"163\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-5.png 367w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-5-300x168.png 300w\" sizes=\"auto, (max-width: 292px) 100vw, 292px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-normal-font-size\">The personal account will open as an additional window<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-7.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-7.png\" alt=\"\" class=\"wp-image-2261\" width=\"484\" height=\"370\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-7.png 602w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-7-300x229.png 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-7-80x60.png 80w\" sizes=\"auto, (max-width: 484px) 100vw, 484px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-large-font-size\">Blocking Undesired Teams Logins in Windows 10<\/p>\n\n\n\n<p>A post from Microsoft explains (also) how to \u201cRestrict sign in to Teams\u201d <a rel=\"noreferrer noopener\" href=\"https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/sign-in-teams#how-to-restrict-sign-in-on-desktop-devices\" data-type=\"URL\" data-id=\"https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/sign-in-teams#how-to-restrict-sign-in-on-desktop-devices\" target=\"_blank\">https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/sign-in-teams#how-to-restrict-sign-in-on-desktop-devices<\/a><br>A paragraph is dedicated to mobile devices and another one to Windows 10 access. For this post I will focus on how to restrict sign-in on desktop devices \/ Windows 10.<br>The policies can be set using<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Device Management solutions such as MDM (Mobile Device Management)<\/strong><\/li><li><strong>GPO (Group Policy Object)<\/strong><\/li><\/ul>\n\n\n\n<p>To use the GPOs, you should install the \u201c<strong>Administrative Template files (ADMX\/ADML) and Office Customization Tool for Microsoft 365 Apps for enterprise, Office 2019, and Office 2016<\/strong>\u201d<br><a rel=\"noreferrer noopener\" href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=49030\" data-type=\"URL\" data-id=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=49030\" target=\"_blank\">https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=49030<\/a><br>Note:<span class=\"has-inline-color has-luminous-vivid-amber-color\"> Supported Operating System for the DC is Windows Server 2016 and Windows Server 2019<\/span><\/p>\n\n\n\n<p>As an alternative, it is possible to apply the required changes to the Windows Registry (I will explain this one after the GPO based approach)<\/p>\n\n\n\n<p class=\"has-large-font-size\">Blocking Logins Using GPOs<\/p>\n\n\n\n<p> To add the required Administrative Templates, download the correct version (X86 or x64) and decompress the files in a folder<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-10.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-10.png\" alt=\"\" class=\"wp-image-2267\" width=\"471\" height=\"140\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-10.png 602w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-10-300x89.png 300w\" sizes=\"auto, (max-width: 471px) 100vw, 471px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-normal-font-size\"><br>You are able to copy the required files into a Central Store ( see the Microsoft document <a rel=\"noreferrer noopener\" href=\"https:\/\/docs.microsoft.com\/en-us\/troubleshoot\/windows-client\/group-policy\/create-and-manage-central-store\" data-type=\"URL\" data-id=\"https:\/\/docs.microsoft.com\/en-us\/troubleshoot\/windows-client\/group-policy\/create-and-manage-central-store\" target=\"_blank\">https:\/\/docs.microsoft.com\/en-us\/troubleshoot\/windows-client\/group-policy\/create-and-manage-central-store<\/a>) and finally use them inside a GPO.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>In my test the Central Store was \\\\test2019.corp\\sysvol\\Test2019.corp\\Policies\\PolicyDefinitions<\/p>\n\n\n\n<p>Using Group Policy Management I have created a policy called &#8220;N<strong>o_Personal_Logins<\/strong>&#8220;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-13.png\"><img loading=\"lazy\" decoding=\"async\" width=\"289\" height=\"67\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-13.png\" alt=\"\" class=\"wp-image-2270\"\/><\/a><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-12.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-12.png\" alt=\"\" class=\"wp-image-2269\" width=\"425\" height=\"194\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-12.png 592w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-12-300x137.png 300w\" sizes=\"auto, (max-width: 425px) 100vw, 425px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>The imported ADMX files are shown in the GPO <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-11.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-11.png\" alt=\"\" class=\"wp-image-2268\" width=\"413\" height=\"422\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-11.png 602w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-11-294x300.png 294w\" sizes=\"auto, (max-width: 413px) 100vw, 413px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>Under <strong>User Configuration &#8211; Administrative Template Policy Definitions &#8211; Microsoft Teams<\/strong> we have a parameter called &#8220;<strong>Restrict Teams Signin to Accounts in Specific tenants<\/strong>&#8221; <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-14.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-14.png\" alt=\"\" class=\"wp-image-2271\" width=\"602\" height=\"441\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-14.png 602w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-14-300x220.png 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-14-80x60.png 80w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>The parameter is set to <strong>Enable<\/strong>, the list of the authorized tenant uses the Tenant IDs (if you want to know it from the domain FQDN I suggest using <a rel=\"noreferrer noopener\" href=\"https:\/\/www.whatismytenantid.com\/\" data-type=\"URL\" data-id=\"https:\/\/www.whatismytenantid.com\/\" target=\"_blank\">https:\/\/www.whatismytenantid.com\/<\/a> ). Each Tenant ID must be separated using comma<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-16.png\"><img loading=\"lazy\" decoding=\"async\" width=\"940\" height=\"879\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-16.png\" alt=\"\" class=\"wp-image-2273\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-16.png 940w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-16-300x281.png 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-16-768x718.png 768w\" sizes=\"auto, (max-width: 940px) 100vw, 940px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-large-font-size\">Windows 10 User Experience<\/p>\n\n\n\n<p>If you try to switch to an unauthorized account, now, you have the message below<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-17.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-17.png\" alt=\"\" class=\"wp-image-2274\" width=\"346\" height=\"398\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-17.png 614w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-17-261x300.png 261w\" sizes=\"auto, (max-width: 346px) 100vw, 346px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>Similar, if you try to start Teams with the unauthorized account<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-18.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-18.png\" alt=\"\" class=\"wp-image-2275\" width=\"349\" height=\"266\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-18.png 564w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-18-300x228.png 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-18-80x60.png 80w\" sizes=\"auto, (max-width: 349px) 100vw, 349px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-large-font-size\">What the GPO Does &#8211; Manual Approach in REGEDIT<\/p>\n\n\n\n<p>As you can see in the image below, a new Registry Key is created<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-19.png\"><img loading=\"lazy\" decoding=\"async\" width=\"544\" height=\"187\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-19.png\" alt=\"\" class=\"wp-image-2276\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-19.png 544w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/05\/image-19-300x103.png 300w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>You have the same result modifying the registry (as for the Microsoft document mentioned before)<\/p>\n\n\n\n<p>Value Name: RestrictTeamsSignInToAccountsFromTenantList<br>Value Type: String<br>Value Data: Tenant ID, or comma-separated list of Tenant IDs<br>Path: use one of the following<br><strong>Computer\\HKEY_CURRENT_USER\\SOFTWARE\\Policies\\Microsoft\\Cloud\\Office\\16.0\\Teams Computer\\HKEY_CURRENT_USER\\SOFTWARE\\Policies\\Microsoft\\Office\\16.0\\Teams Computer\\HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\16.0\\Teams<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Teams &#8211; Blocking Logins to Personal Accounts &#8211; Blocking Logins to Accounts in Unapproved Tenants<\/p>\n","protected":false},"author":1,"featured_media":2281,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","footnotes":""},"categories":[765,753,752,757],"tags":[762,759,751,77,755],"class_list":["post-2253","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-765","category-microsoft365","category-microsoft-teams","category-office-365","tag-microsoftteams","tag-microsoft-365","tag-microsoft-teams","tag-office-365","tag-teams"],"_links":{"self":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2253"}],"version-history":[{"count":7,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2253\/revisions"}],"predecessor-version":[{"id":2282,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2253\/revisions\/2282"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/media\/2281"}],"wp:attachment":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}