MFA - No internet Connection - Rules Firewall

Adiel Machado 0 Reputation points
2024-09-24T12:31:49.4833333+00:00

evidenciaMFA

Hello, I hope everyone is doing well!

Apologies for my English, as I am not fluent.

I am experiencing difficulties in segregating a wireless network for exclusive use by a digital timekeeping system (employee attendance records). The platform's authentication relies on Two-Factor Authentication, which must be correctly installed on the employee's personal smartphone. Although access to the tool is seamless and prompts for two-factor authentication, indicating that a notification will be sent to the phone and that the generated code in the app is required, the Authenticator app fails to establish communication. Upon opening the app, the immediate notification is: "Check your internet connection and try again."

The current policy permits the following IPs on any port (I am unsure if the community will censor these IPs):

20.20.32.0/19

20.190.128.0/18

20.231.128.0/19

40.126.0.0/18

52.159.5.240/28

52.159.7.16/28

52.247.73.160/28

52.250.84.176/28

52.250.85.96/28

52.251.8.48/28

70.37.154.128/25

70.37.154.128/25

134.170.116.0/25

134.170.165.0/25

13.107.6.171/32

13.107.18.15/32

13.107.140.6/32

52.108.0.0/14

52.244.37.168/32

13.107.6.192/32

13.107.9.192/32

Is it necessary to authorize another IP, or does the app require specific communication with a destination other than Microsoft to function?

Note: Currently, this has only been tested on Android devices.

Note 2: Please consider that due to equipment limitations, I can only authorize connections by IP or by complete FQDNs without wildcards.

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
6,945 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Adiel Machado 0 Reputation points
    2024-09-24T12:43:04.0933333+00:00

    The end of the text was in Portuguese and the site is showing errors when editing... finishing:

    Should I release another IP or does the APP depend on some specific communication with some other destination other than Microsoft to work?

    Note: For now, tested only on Android phones.

    Note 2: Please take into account that due to limitations on some equipment, I can only release the connection by IP or by FQDNs without wildcards, that is, if it is by FQDNs, I need to have the complete URL.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.