Security
Azure Support Agent runs in the deployed environment and is designed around read-only defaults, explicit write approvals, tenant scoping, RBAC/SSO, encrypted credentials, and audit records. Security still depends on deployment configuration, provider contracts, Azure/Graph grants, and administrator choices.
Guides
Procedures
| Task | Recipe |
|---|---|
| Create users, roles, and groups, and connect an SSO provider | Manage users, roles, groups, and SSO |
| Set password, lockout, and session policy, and revoke a session | Set policy and revoke sessions |
| Restrict which IP addresses can reach the application | Restrict network access by IP |
| Store and rotate Azure and provider credentials | Manage Azure tenants |
| Review privileged actions and export them to a SIEM | Review usage and audit history |
See the permissions reference for the capability keys behind every gate.
Use no real secrets or identifiers in examples. Report product vulnerabilities through the repository’s security process rather than a public issue.