Share via

Azure AD Conditional Access Policy Country Blocking

DutchIvan 31 Reputation points
2022-12-19T20:14:37.897+00:00

Country blocking has been working well in regards to not allowing access from countries that are not approved. However, with country blocking we still get numerous login attempts from malicious users from countries that are blocked that trigger either an account lock or require the user to re-authenticate which is very cumbersome.

Any guidance would be appreciated, thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Answer accepted by question author
  1. Dillon Silzer 60,816 Reputation points Volunteer Moderator
    2022-12-20T02:58:33.267+00:00

    Hi @DutchIvan

    Check your policies with Cloud App Security:

    1) Go to https://portal.cloudappsecurity.com/

    2) Go to Control > Policies

    272257-image.png

    3) Open the following policies:

    272220-image.png

    4) Check your Governance actions (and I'd recommend to uncheck the following unless you want this type of behaviour to continue disrupting your users):

    272321-image.png

    Note: If you have a tight security policy, keep these checked, but I happen to have the same thing going on and if this is checked off it is creating a kind of DoS (Denial of Service) attack.


    If this is helpful please accept answer.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. DutchIvan 31 Reputation points
    2022-12-20T15:24:33.43+00:00

    DillonJS,

    Thanks for the thoughtful reply with screenshots. That is a great idea to look at and illuminated something else I need to look into. I don't have those governance options I can only select office 365 which has two options under it suspend and confirm user compromised. So I will look at our settings to see if I am missing something.

    Anyway the actual solution was an issue we had with a conditional access policy that we had set to block legacy authentication. Other clients like POP, IMAP, SMTP were being blocked but didn't check Exchange ActiveSync authentication requests. Enabling this cut about 700 malicious login attempts a day and ultimately will prevent users from getting locked out with that method.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.