About SharePoint Conditional Access Control

Cliff 91 Reputation points
2023-12-15T01:45:02.51+00:00

Hi All,

Assuming we have set rules for unmanaged and network location on the SharePoint admin center,

The purpose is to block unmanaged or non compliant IP from accessing OneDrive, but Teams can be used.

Can we set "unmanaged but within location IP" or "non network location IP but managed device" any of both rules can access Sharepoint ?

Thanks

Microsoft 365 and Office | SharePoint | For business | Windows
Microsoft 365 and Office | OneDrive | For business | Windows
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Akshay-MSFT 18,011 Reputation points Microsoft Employee Moderator
    2023-12-15T06:09:55.8+00:00

    @Cliff

    Thank you for posting your query on Microsoft Q&A, from above description I could understand that you are trying to Block access to SharePoint when:

    • Device is not in Trusted network Location.

    OR

    • Device is non complaint/unmanaged.

    Please do correct me by responding in the comments section:

    • For a Trusted IP location, kindly define an IP range named location.
    • Then define a Location based condition including All locations but excluding the "Trusted location"

    User's image

    • In the access control define "Grant Access" with device to be "Complaint"

    User's image

    • Now this CA policy will be evaluating only devices from "Non-Trusted" locations/network for their compliant status, device from "Trusted" network will bypass this policy.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer (Yes)" and "share your feedback ". This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.