We oversee multiple schools that have transitioned to a cloud-based infrastructure without maintaining any on-site servers. To accommodate this shift, we've set up Microsoft 365 accounts for all individuals, including students. As you might be aware, starting in March, Microsoft will mandate the use of Two-Factor Authentication (2FA), a move that presents significant challenges, especially for our student users. To address this, we're considering implementing a conditional access policy that would waive the 2FA requirement when users are connected to the school's network. We're in discussions with the LCC to facilitate this through the use of their external IP addresses as designated trusted locations. The hurdle we're facing is the initial mandate for users to configure 2FA, which serves as a "baseline" security measure. This requirement could potentially disrupt the user experience significantly, especially since our schools with hybrid server setups, currently rely on Single Sign-On (SSO) policies. Does anyone know of any solutions or workarounds?