ASD's Blueprint for Secure Cloud

Tenancy Isolation

This section describes the design decisions associated with blocking external tenants from establishing connections into the tenant for system(s) built using ASD's Blueprint for Secure Cloud.

Estimated reading time: 2 minutes

With tenant restrictions, the organisation can control access to Software-as-a-Service (SaaS) cloud applications, based on the Entra ID tenant the applications use for single sign-on. With tenant restrictions, the organisation can specify the list of tenants that their users are permitted to access. Entra ID then only grants access to these permitted tenants using Entra ID based tenant restriction.

Additionally, if the organisation wants to enforce tenant isolation for Microsoft Power Platform connections, then they can use Power Platform’s tenant isolation capability. Note that the Power Platform tenant isolation feature does not impact Entra ID based access outside of Power Apps and Power Automate. Power Platform tenant isolation only works for connectors using Entra ID based authentication such as Office 365 Outlook or SharePoint.

Organisations wanting to block connectors that use external identity providers such as Microsoft account, Google, etc., can create a data loss prevention policy and classify the connector under the Blocked group. See Connectors and Data Loss Prevention Policies.

Power Platform tenant isolation ability is available with two options: one-way or two-way restriction.

Security & Governance

  • None identified

Design

  • None identified

Configuration

  • None identified

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra