Work from another country

J-3804 1,601 Reputation points
2023-08-29T22:51:20.0433333+00:00

Hi Team,

We have a geo-location policy in place. We want to make an exception for a user to work from another country. We want to mitigate any risk by working from that location. Are there any additional measures we can put in place on the user's account or device to ensure he works securely?

Thank you for your help,

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,570 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,184 questions
0 comments No comments
{count} votes

Accepted answer
  1. Michael Smith 2,926 Reputation points Microsoft Employee
    2023-08-30T09:03:31.0666667+00:00

    Hi Jennifer,

    Thank you for contacting the community forums.

    You can exclude the users IP range from the Conditional access policy if you their IP will be be constant. Or you can exclude the country.

    User's image

    Another option you may consider is to exclude by device filtering.

    You have various properties you can exclude by.

    Trust Type: azure ad joined, registered, hybrid,

    DeviceID

    Device ownership

    etc...

    User's image

    In regards to securing the users account. you can enforce MFA via CA policy and perhaps consider bitlocker encryption for the device.

    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices

    Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.