Avatar of Zoldy2000
Zoldy2000
Flag for Canada asked on

How to limit a domain account in hybrid office 365 deployment to only office 365 logon

How to limit a domain account in hybrid office 365 deployment to only office 365 logon.    No local domain access or logon privileges.

User existed already and used to have local domain privileges and logon rights.

User now is remote and permanently only requires access to his office 365 email.      We want to remove all domain privileges and logon rights.      Is there an easy way to accomplish this as some rights may be explicit.

For example can we deny all logons accept office 365?
Microsoft OfficeMicrosoft 365

Avatar of undefined
Last Comment
Zoldy2000

8/22/2022 - Mon
Vasil Michev (MVP)

How are your users authenticating against O365? Generally speaking, they dont need any local rights to work with O365 services. You can even disable the account, unless you are using AD FS/PTA or any other form of authentication that relies on the on-premises AD.
Zoldy2000

ASKER
We are in a hybrid setup and using AD sync to authenticate
Alan Cox

If just using hash sync, the authentication for O365 isn't relying on windows active directory.
Your help has saved me hundreds of hours of internet surfing.
fblack61
Zoldy2000

ASKER
Our Office 365 accounts are authenticating using our Active Directory that I know for sure.    i want to keep this while limiting this account.
ASKER CERTIFIED SOLUTION
Justin Hannah

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Zoldy2000

ASKER
Restricting the logon is exactly what I was looking for.   I simply restricted logons to a non existing computer name.