Jump to content

Recommended Posts

Posted

Does anyone know if its possible to skip the MFA setup from within my trusted IP range?

 

Basically I want all users to have MFA however I only want Office365 to prompt them to set this up when they are outside of my trusted IP range

Posted
Yes it is possible within Office 365 but not sure if works on all licences?

 

Help here https://www.bettercloud.com/monitor/the-academy/how-to-whitelist-ip-addresses-for-multi-factor-authentication/

 

Yes I have this setup already, what it doesn't do is skip the setup process entirely, its still mandatory to setup MFA and once its set it will not ask again - I don't want this to happen, I only want Azure to require MFA setup when the user it outside our trusted IP scope

Posted

Here is the issue with that

 

1) Some teachers refuse to use their personal device to authenticate their office365 account and therefore will not access office365

2) Some users do not have a mobile device or access to a phone to complete the request

3) I need to set this up for students, or SLT do not allow use of phones within class

 

What's happening at the moment is our homepage is set to sharepoint online with SSO, students cannot access the homepage or their office365 experience just because they cannot setup MFA (for whatever reason, some have managed it but a majority haven't)

 

It would by great if i could bypass the setup process from my trusted IP range, its useless anyway since it is bypassed - Surely asking the user to setup MFA when outside the trusted scope is a better method of forcing them to setup whilst in a trusted scope

Posted

Ask them to use SMS or an alternative email account as their 2nd form of authentication.

I don;t think there is a way to do what you want.

 

Here is the issue with that

 

1) Some teachers refuse to use their personal device to authenticate their office365 account and therefore will not access office365

2) Some users do not have a mobile device or access to a phone to complete the request

3) I need to set this up for students, or SLT do not allow use of phones within class

 

What's happening at the moment is our homepage is set to sharepoint online with SSO, students cannot access the homepage or their office365 experience just because they cannot setup MFA (for whatever reason, some have managed it but a majority haven't)

 

It would by great if i could bypass the setup process from my trusted IP range, its useless anyway since it is bypassed - Surely asking the user to setup MFA when outside the trusted scope is a better method of forcing them to setup whilst in a trusted scope

Posted
It's just set up on the next login whereever they are. The only way around that would be to enable it before the end of the day and tell them not to log in until they get home. Still think it's daft though, the other problems are procedural; if people don't want to abide then it's their problem - the school have to protect their data and their staff, its of their benefit.
Posted
Ask them to use SMS or an alternative email account as their 2nd form of authentication.

I don;t think there is a way to do what you want.

 

looking at MFA service settings alternative email is not available:

 

 

Methods available to users:

 

Call to phone

 

Text message to phone

 

Notification through mobile app

 

Verification code from mobile app or hardware token

Posted
Foot down time. "If you don't want to use a personal device whether its a phone or tablet for this purpose, then you'll not be able to use services outside school. Please remember that school is locked up at 7pm to help with the extra workload."

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...