Jump to content

Recommended Posts

Posted

Good morning all,

 

I'm in the process of setting up MFA for Office 365 for our staff, I'm using conditional access policies to do this and the testing has gone well.

 

I used the Combined Security Registration Info method to get a test user to register (this worked and SSPR is fully working).

 

Then set a conditional access policy to require MFA for Office 365, this is also working except it asks at every login even inside the network despite me thinking I have set it to not ask inside the network by ticking 'Skip multi-factor authentication for requests from federated users on my intranet'

 

Something I'm missing?

 

Thanks

Posted

Slightly different methodology, but it might give you somewhere to look or something else to try.

We did it by setting up the school's external IPs as a named location in Azure>Conditional Access, and then having the location as an exclusion from the MFA policy.

Posted

@Rob_D

 

So if I'm following that correctly you've set it up so your users don't get prompted for MFA outside of the network?

 

I'm coming at this from the angle of exclusion = place you don't want users to be prompted for MFA

 

So I'm trying to exclude MFA prompts internally but include them externally

Posted

We've got it set up so users have to use MFA externally, but NOT from devices on our network (or more specifically devices connecting to 365 through our internet connection).

Which I think is the same as you, right?

 

In the MFA Policy, we have the school network (our external IP addresses because that's what 365 sees as "our network") set up as an exclusion. So login requests coming from school IP addresses are excluded from the policy and thus not prompted for MFA but requests from anywhere else are.

 

Does that make sense.

Posted

As above.

 

Staff MFA enabled for "Any Location" with "Trusted locations excluded".

 

Make sure you set your named location (of internal IPs) as 'trusted'.

 

Screenshots attached.

 

Peter

MFA_3.png

MFA_2.png

MFA_1.png

  • Thanks 1
Posted
Good morning all,

 

I'm in the process of setting up MFA for Office 365 for our staff, I'm using conditional access policies to do this and the testing has gone well.

 

I used the Combined Security Registration Info method to get a test user to register (this worked and SSPR is fully working).

 

Then set a conditional access policy to require MFA for Office 365, this is also working except it asks at every login even inside the network despite me thinking I have set it to not ask inside the network by ticking 'Skip multi-factor authentication for requests from federated users on my intranet'

 

Something I'm missing?

 

Thanks

 

Don’t use that setting. That setting means ‘look for a claim called insidecorporatenework’ which is issued by the ADFS server if the client can see the inside network interface of the ADFS server. Hopefully you’re not using ADFS or similar so it’ll never work

 

Make sure to use the proper internet IPs as your trusted IPs (e.g. not the 10.x address). And also consider a registration policy that only works inside the school.

Posted

@Rob_D that makes sense now thank you.

@howart_p when you say internal you mean the proper internet\external IPs as @Rob_D and @chaplic have suggested?

@chaplic I did read about that setting and ADFS which we aren't using so figured it might not be relevant or there would be an updated way to achieve the desired outcome.

 

In the settings for my named locations I have what was left by my predecessor, 'Name of My School' (with a single IP address that looks like it could be external), this is marked as Trusted and I've added it to the excluded locations on the Conditional Access policy. Maybe that IP address isn't right or has changed.

 

In the Conditional Access policy I also have an exclusion for 'Multifactor authentication trusted IPs', I don't know where this has come from unless it's generated by me having the "Skip multi-factor authentication for requests from federated users on my intranet" box ticked?

 

Thanks again

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...