Admin notification for excluded service accounts and CA policy impact
When OneClickComply deploys a service account into a customer's tenant, that account may be excluded from Conditional Access policies. The admin is not proactively informed about this exclusion, which creates a blind spot — they may not realise their CA policies don't apply to the OCC service account. Similarly, if the tenant has security defaults or CA configurations that conflict with OCC's requirements, there is no upfront communication about it.
Proposed Solution:
1. During or immediately after integration setup, display a clear notification to the admin listing any CA policies the OCC service account is excluded from.
2. If the tenant has security defaults enabled that may conflict with OCC, surface a warning with guidance on what to review or adjust.
3. Include this information in the post-setup email and make it accessible from the integration side panel under a 'Security notes' or 'Configuration notices' section.
4. If CA policy exclusions change on subsequent scans, notify the admin of the change.
Acceptance Criteria:
1. Admin is shown which CA policies the OCC service account is excluded from during or after setup.
2. Conflicting security defaults trigger a visible warning with remediation guidance.
3. Information is accessible from the integration side panel post-setup.
4. Changes to CA exclusions on subsequent scans generate a notification.
Log in to comment and vote
No comments yet
Be the first to share your thoughts.