How to Restrict access to Sharepoint Online sites only for user using App in AAD

Viewed 126

I am relatively new in Sharepoint and Azure, i got a task to recreate a case of logging to sharepoint online site using powershell with m365 cli and TenantID and AppID environmentals, so i need to log in using something like this:

$env:CLIMICROSOFT365_AADAPPID="someidkey"

$env:CLIMICROSOFT365_TENANT="sometenantidkey"

m365 login --authType password --userName "testuser@domain.onmicrosoft.com" --password "somepassword"

I know it works on ot her apps

As for now i created Application in Azure Active Directory

in authentication i added mobile and deskotp application and checked https://login.microsoftonline.com/common/oauth2/nativeclient

i allowed public client flows

in api permission i putted Sharepoint Delegated AllSites.Write I Used Assignment required for application and i assigned application to "testuser"

Lets call this app: "Update Sharepoint"

Then i went to my sharepoint online site, used /_layouts/15/AppInv.aspx to grant permission putted in App ID: ID for "Update Sharepoit" in App Domain: domain.onmicrosoft.com in Redirect url: http://domain.onmicrosoft.com and in xml request

<AppPermissionRequests><AppPermissionRequest Scope="http://sharepoint/content/sitecollection/web" Right="FullControl" /></AppPermissionRequests>

My user is native user so he has disabled mfa, and is in member group of sharepoint site

However i can still just log in using just login and password and update the sharepoint site, using powershell.

What am i missing? How can i restrict sharepoint site that it needs to accept TenantID and AppID

0 Answers
Related