---
sourceDocument: Australia Conversational Interfaces
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/conversational-interfaces

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Conversational Interfaces

ft:clusterId :

    - convint

bundleId :

    - convint

workflow :

    - Platform


---

# Configure Microsoft Azure Conditional Access for Microsoft Teams tenant

# Configure Microsoft Azure Conditional Access for Microsoft Teams tenant {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

You must configure conditional access in Microsoft Azure to restrict
users from accessing the production applications. Conditional access helps you from
accidentally overriding your production integration with a custom or personal instance
integration.

## Antes de Iniciar

Roles required: virtual_agent_admin and user with Azure admin access.

## Procedimento

1. Log in to [Microsoft Azure portal](https://portal.azure.com/).
2. Search for Azure AD Conditional Access.
3. Navigate to New PolicyCreate New Policy and provide the policy a name.\<p\>  

4. Under Users or Workload identities, select 0 users or workload identities selected.  
   A What does this policy apply to? pop-up is displayed.
5. Under Include, select All users.  

   Nota:  
   Selecting All users will include the users in the restriction policy.
6. Under Exclude, select Users and groups to exclude admin users who have access to override the tenant.  

7. Under Select excluded users, select 0 users and groups selected to select an admin user and select Select.
8. Under Cloud apps or actions, choose which assets to protect.  
   For example, the NowBot or whatever the name of the ServiceNow bot is in Azure.
9. Under Grant, select 0 controls selected and select Block access.
10. In the Enable policy section, select On to turn on the Report-only function.
11. Select Create.  
    After the ACL (Access Control List) is configured, it takes about 15 minutes fr the synchronization.

## Resultado

After the policy is created and the synchronization is complete, it restricts any user except the admins from overriding the tenant accidentally.  

Nota:  
The restriction does not affect the restricted users from using the Microsoft Teams or the Now Virtual Agent.

