Share via

Skip multifactor authentication for requests from following range of IP address subnets gets ignored

nettech 176 Reputation points
2024-09-30T23:49:55.4033333+00:00

Hi,

We have MFA enforced on all of our user and "Skip multifactor authentication for requests from following range of IP address subnets" is set up with our Public IP address. (Configured under Per-user multifactor authentication)

When users access azure portal from home they are prompted for user id, password and MFA this is working as expected, at the office everyone is getting MFA prompt despite having our WAN IP configured as an exclusion.

What else could be missing?

Thank you!

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Microsoft Security | Microsoft Authenticator
Microsoft Security | Intune | Other
Microsoft Security | Microsoft Entra | Other
0 comments No comments

Answer accepted by question author

  1. Sandeep G-MSFT 21,151 Reputation points Microsoft Employee Moderator
    2024-10-03T04:18:47.4633333+00:00

    @nettech

    Thank you for posting this in Microsoft Q&A.

    As I understand you have configured MFA settings to prompt for MFA only when users are accessing Azure resources from external network (Internet). Users should not be prompted for MFA when accessing Azure resources from internal network.

    You can try to achieve this by configuring a conditional access policy in Azure.

    You can define a conditional access policy by mentioning IP addresses range which should prompt for MFA while accessing Azure resources. You can configure this in Named locations in Conditional access policy. Once you create Named locations you can use this Named location in the conditional access policy that you create.

    You can follow below article to configure CA policy with named locations using network IP ranges for MFA prompts.

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-assignment-network

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    Was this answer helpful?

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.