Share via

Microsoft Security (training)

Kerolose Adel 0 Reputation points
2026-04-19T10:31:15.2833333+00:00

hi

we have created Attack simulation training and assigned a training for users who is phished, but we faced issue as the users cannot access Microsoft Security Training because they don't have access and the reason for that, we have a Conditional access rule to block non admins from login to "Microsoft Admin Portals"

so how to avoid that and allow Microsoft security Training Only without allowing all users to " Microsoft Admin Portals"

Microsoft 365 and Office | Microsoft 365 Defender | Other | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-19T10:31:27.4033333+00:00

    Microsoft Security training for Attack simulation training is delivered through the Microsoft Defender portal, which is part of the Microsoft Admin Portals app grouping in Conditional Access. Because the Conditional Access policy blocks non-admins from accessing Microsoft Admin Portals, targeted users are also blocked from opening the training.

    To allow users to access only the Attack simulation training experience while still enforcing strong controls on admin access, adjust Conditional Access as follows:

    1. Keep the existing policy that targets Microsoft Admin Portals for admins (for example, require MFA for admin roles), rather than blocking all non-admin users from the Microsoft Admin Portals app.
    2. If a block policy is required, avoid applying a blanket Block access to all users for Microsoft Admin Portals. The documentation notes that this grouping is intended primarily for include scenarios (for example, enforcing MFA), not as a bulk exclusion mechanism for all backend services.
    3. Instead of blocking all non-admins from Microsoft Admin Portals, use Grant controls (such as MFA or Terms of use) for the Microsoft Admin Portals app and scope them to:
      • Admin roles only (for example, Global Administrator, Security Administrator), or
      • A security group that contains only admins.
    4. Ensure regular users are not included in any Block policy that targets Microsoft Admin Portals, so that when they follow the training link from Attack simulation training, they can reach the Microsoft Defender portal and complete the assigned modules.

    If more granular separation is needed, use sign-in logs and Conditional Access audience reporting to identify the specific resource IDs used during training access, then refine policies accordingly. However, the documented and supported pattern is to use Microsoft Admin Portals for protecting admin access (typically with MFA), not to block all non-admin access.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.