How do I block a specific IP address range from logging into Microsoft 365?

Ted Jones 0 Reputation points
2024-07-29T17:41:19.6866667+00:00

I have a user in Sweden. MFA is enabled on his account but there consistently shows a login from Diamond Bar California. The user claims that he does not use a VPN service and is not logged in during the times that the login log shows. The IP address range is consistent. How can I block the ip address range?

The login audit shows

Multifactor authentication: Status Success

Continuous access evaluation: No

Additional Details: MFA requirement satisfied by claim in the token

Thanks

Ted

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Abiola Akinbade 29,405 Reputation points Volunteer Moderator
    2024-07-29T22:04:55.48+00:00

    Hello Ted Jones,

    Thanks for your question

    With the location condition in Conditional Access, you can control access to your cloud apps based on the network location of a user. You can do this by following the steps here: Conditional Access: Block access by location

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    Regards,

    Abiola


  2. Sandeep G-MSFT 20,906 Reputation points Microsoft Employee Moderator
    2024-07-30T04:25:59.33+00:00

    @Ted Jones

    Thank you for posting this in Microsoft Q&A.

    As I understand you want to block a user sign-in from one specific IP range as you are seeing some untrusted sign-ins from few IP addresses for this user.

    Yes, you can block this IP range in Entra ID. As Akinbade Abiola mentioned above you can utilize Conditional access feature in Entra ID to block specific IP ranges sign-ins.

    Microsoft Entra Conditional Access brings signals together, to make decisions, and enforce organizational policies.

    Conditional Access policies at their simplest are if-then statements; if a user wants to access a resource, then they must complete an action.

    Yes, using this feature requires Microsoft Entra ID P1 licenses. To find the right license for your requirements, see Compare generally available features of Microsoft Entra ID.

    Customers with Microsoft 365 Business Premium licenses also have access to Conditional Access features.

    You can configure conditional access policy based on IP range. You will have to first create a named location in Entra ID using those required IP ranges.

    Post that you can use created named locations in conditional access policies.

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-policy-location

    Let us know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.