<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Access and Microsoft Tenant Restrictions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251093#M126205</link>
    <description>&lt;P&gt;You need to put Tenant ID value on "&lt;SPAN&gt;restrict-access-context&lt;/SPAN&gt;&lt;SPAN&gt;".&lt;BR /&gt;&lt;BR /&gt;P.S. Ensure you block QUIC.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Mar 2026 18:28:02 GMT</pubDate>
    <dc:creator>acsebav</dc:creator>
    <dc:date>2026-03-27T18:28:02Z</dc:date>
    <item>
      <title>Prisma Access and Microsoft Tenant Restrictions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251025#M126201</link>
      <description>&lt;P&gt;Hello All . Been wrestling with this for a week .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My starting point is&amp;nbsp; to only allow connections to the entra joined domain&amp;nbsp; for e,g,&amp;nbsp; fred.onmicrosoft.com&amp;nbsp; &amp;nbsp;.&lt;/P&gt;
&lt;P&gt;The rational is DLP - if I go to my browser and attempt to logon to another enterprise - dave.onmicrosoft.com it is blocked.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not consumer BTW - home tenants are blocked with&amp;nbsp; the tenant restrictions I am about to describe...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For background , Entra&amp;nbsp; has V1 &amp;amp; V2 implementations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The palo method is :&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create a URL filter with the correct microsoft login domain .&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Decrypt them&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;For V1 use header insertion -&amp;nbsp;
&lt;UL&gt;
&lt;LI&gt;restrict-access-context : tenant value&amp;nbsp; (login.microsoftoneline.com/login.microsoft.com/login windows.net )&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;restrict-access-to-tenant : tenantvalue (same as above&lt;/LI&gt;
&lt;LI&gt;sec-restrict-tenant-access: restrict msa&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;V2 is just&amp;nbsp;
&lt;UL&gt;
&lt;LI&gt;sec-restrict-tenant-access-policy : tenant value&amp;nbsp; (same microsoft logins as above)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Then create a rule with a security profile with header &amp;amp; URl filter - restrict it to a test user !&lt;/P&gt;
&lt;P&gt;Basically you&amp;nbsp; decrypt microsoft logins an insert a header....&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Test the logins from login.microsoftonline.com&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to setup tenant restrictions on Entra with block inwards and outwards .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The idea is you pass the header to Entra and it decides whether you connect .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem is it doesnt work !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can login to eberything...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only way I have managed to get this to psuedo work is to use SaaS endpoint for M365&amp;nbsp; &amp;nbsp;on a rule&amp;nbsp; with no header insertion .&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Only problem is - it stops the entra joined user &lt;A href="mailto:greg@fred.onmicrosoft.com" target="_blank"&gt;greg@fred.onmicrosoft.com&amp;nbsp;&lt;/A&gt;&amp;nbsp; logging into &lt;A href="mailto:dav@microsoftonline.com" target="_blank"&gt;dave@onmicrosoft.com&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I doesnt stop &lt;A href="mailto:dave@onmicrosoft.com" target="_blank"&gt;dave@onmicrosoft.com &lt;/A&gt;from logging into &lt;A href="mailto:dave@onmicrosoft.com" target="_blank"&gt;dave@onmicrosoft.com&lt;/A&gt;&amp;nbsp;which sort of deefats the object.&lt;/P&gt;
&lt;P&gt;Did anyone get it working ????&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 16:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251025#M126201</guid>
      <dc:creator>gcollins5</dc:creator>
      <dc:date>2026-03-26T16:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access and Microsoft Tenant Restrictions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251093#M126205</link>
      <description>&lt;P&gt;You need to put Tenant ID value on "&lt;SPAN&gt;restrict-access-context&lt;/SPAN&gt;&lt;SPAN&gt;".&lt;BR /&gt;&lt;BR /&gt;P.S. Ensure you block QUIC.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 18:28:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251093#M126205</guid>
      <dc:creator>acsebav</dc:creator>
      <dc:date>2026-03-27T18:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access and Microsoft Tenant Restrictions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251155#M126210</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You need to put Tenant ID value on "&lt;/SPAN&gt;&lt;SPAN&gt;restrict-access-context&lt;/SPAN&gt;&lt;SPAN&gt;". - did you use the tenant name or the value from entra ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I tried both with no result .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Quic is blocked already so I don't think it is that .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 07:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251155#M126210</guid>
      <dc:creator>gcollins5</dc:creator>
      <dc:date>2026-03-30T07:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access and Microsoft Tenant Restrictions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251158#M126211</link>
      <description>&lt;P&gt;The value from Entra "Tenant ID".&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 08:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-and-microsoft-tenant-restrictions/m-p/1251158#M126211</guid>
      <dc:creator>acsebav</dc:creator>
      <dc:date>2026-03-30T08:13:15Z</dc:date>
    </item>
  </channel>
</rss>

