Jump to content

Require MFA for external access - Office 365


Recommended Posts

Guest Guest
Posted

Hi all,

 

Today I have been looking at setting up MFA for external access with a whitelist for our public iP so when a user logs in to their office 365 on our network they aren’t prompted for MFA but when they log on their phones, laptops on their home network they do get prompted for MFA.

 

How would I go about setting this up as I’m scratching my head with this one?

Guest Guest
Posted
Hi all,

 

Today I have been looking at setting up MFA for external access with a whitelist for our public iP so when a user logs in to their office 365 on our network they aren’t prompted for MFA but when they log on their phones, laptops on their home network they do get prompted for MFA.

 

How would I go about setting this up as I’m scratching my head with this one?

You do that via conditional access, you require at least an AzureAD P1 license for that though
Posted
You do that via conditional access, you require at least an AzureAD P1 license for that though

 

That is a license for everyone isn’t it, not just those that you want to ensure the policy on?

Posted (edited)

Azure AD P1 licences aren't enforced, they're just done on trust. One single licence enabled the feature for the entire tenant, fairly sure that you only really need to be licensing the users who it will apply to, rather than everyone. Unfortunately can't remember where I saw the explanation/discussion.

 

This then enables the "Trusted Locations" section on the old style MFA screen (https://account.activedirectory.windowsazure.com/usermanagement/mfasettings.aspx) , and also the full Conditional Access section within Azure AD portal.

 

You'll want to set up a rule to only permit MFA sign up from trusted IPs or trusted devices, to prevent a leaked credential being used to log in to an MFA protected account which hasn't completed setup yet, from the attacker just setting up the MFA to their own throwaway device/app.

 

If you've got school owned devices (laptops etc) which are joined (or hybrid joined) to Azure AD, you can use the fact it's a known device to satisfy the MFA requirements as well or instead of using the school IP address.

 

Edit: If you've got M365 A3/E3 you already have licenses for AADP1 included, and A5/E5 includes AADP2.

Edited by Katy
  • Thanks 1
Guest Guest
Posted

Thanks for the replies, I’m going to get cracking on that so it can be done before Tuesday.

 

Thank you! [emoji4]

Guest Guest
Posted
I’ve got Microsoft 365 E5 Licenses which I think comes with P2 because it does say I’ve got them so that’s good \0/ but I can’t find a template or I am struggling to understand how I actually set it up in the new policy but because I have created a location but it changes back to grant mfa when I want it to not show it if that make Sense

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...