Why does ODR need an Azure AD service account in the tenant to backup and restore Conditional Access Policies, MFA and Application Proxy settings? (4369644)
Why does ODR need an Azure AD service account in the tenant to backup and restore Conditional Access Policies, MFA and Application Proxy settings?
説明
Why does ODR need a service account in Azure AD in the tenant to backup and restore Conditional Access Policies, MFA and App Proxy settings and does not use the API access that was granted via an Admin consent process?
対策
ODR is using internal MS API that allows only username\password access in order to achieve backup and restoring of default policies and other components that cannot be backed up and restored via official GRAPH API. We are actively working with Microsoft to get all all objects to be backed up via GRAPH API but for now it is not possible and we had to introduce the service account.