Guest Guest Posted April 30, 2022 Posted April 30, 2022 Hi all, Today I have been looking at setting up MFA for external access with a whitelist for our public iP so when a user logs in to their office 365 on our network they aren’t prompted for MFA but when they log on their phones, laptops on their home network they do get prompted for MFA. How would I go about setting this up as I’m scratching my head with this one?
Guest Guest Posted April 30, 2022 Posted April 30, 2022 Hi all, Today I have been looking at setting up MFA for external access with a whitelist for our public iP so when a user logs in to their office 365 on our network they aren’t prompted for MFA but when they log on their phones, laptops on their home network they do get prompted for MFA. How would I go about setting this up as I’m scratching my head with this one?You do that via conditional access, you require at least an AzureAD P1 license for that though
snagrat Posted April 30, 2022 Posted April 30, 2022 You do that via conditional access, you require at least an AzureAD P1 license for that though That is a license for everyone isn’t it, not just those that you want to ensure the policy on?
Katy Posted April 30, 2022 Posted April 30, 2022 (edited) Azure AD P1 licences aren't enforced, they're just done on trust. One single licence enabled the feature for the entire tenant, fairly sure that you only really need to be licensing the users who it will apply to, rather than everyone. Unfortunately can't remember where I saw the explanation/discussion. This then enables the "Trusted Locations" section on the old style MFA screen (https://account.activedirectory.windowsazure.com/usermanagement/mfasettings.aspx) , and also the full Conditional Access section within Azure AD portal. You'll want to set up a rule to only permit MFA sign up from trusted IPs or trusted devices, to prevent a leaked credential being used to log in to an MFA protected account which hasn't completed setup yet, from the attacker just setting up the MFA to their own throwaway device/app. If you've got school owned devices (laptops etc) which are joined (or hybrid joined) to Azure AD, you can use the fact it's a known device to satisfy the MFA requirements as well or instead of using the school IP address. Edit: If you've got M365 A3/E3 you already have licenses for AADP1 included, and A5/E5 includes AADP2. Edited April 30, 2022 by Katy 1
Guest Guest Posted April 30, 2022 Posted April 30, 2022 Thanks for the replies, I’m going to get cracking on that so it can be done before Tuesday. Thank you! [emoji4]
Guest Guest Posted May 2, 2022 Posted May 2, 2022 I’ve got Microsoft 365 E5 Licenses which I think comes with P2 because it does say I’ve got them so that’s good \0/ but I can’t find a template or I am struggling to understand how I actually set it up in the new policy but because I have created a location but it changes back to grant mfa when I want it to not show it if that make Sense
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now