Workaround:
1.- Launch the Active Roles Server MMC console
2.- Navigate to the following: Configuration | Access Templates
3.- Right-click on the Access Templates container and select New | Access Template
4.- Provide a name for the access template such as, "Deny - Modify Azure License":

5.- Click Add, select 'Only the following classes' and check off 'EDS-Azure-User', click Next:

6.- Select 'Object property access', check off 'Deny permission', check off 'Write properties', click Next:

7.- Select 'The following properties' and check off 'Show all possible properties', check off 'edsaAzureSubscribedSkus', click Finish:

Repeat the same steps for the class 'User'
It should be listed the permission as 'Deny, Write edsaAzureSubscribedSkus, User' and 'EDS-Azure-User', click Next:

Once the Access Template is created, it can be assigned to the appropriate scope and users/groups to deny access to the 'License from Azure Properties' for hybrid user accounts.
If the same is required for cloud-only users, assign it as well at the container Configuration from the Active Roles MMC.

Status:
NA
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center