Will Microsoft Graph support service tags for IP-based Conditional Access Policies?

Alyssa Williams (ODSP) 20 Reputation points Microsoft Employee
2025-04-29T22:22:01.13+00:00

Hi,
I work on a tenant factory microservice. Our job is to provision tenants for internal use to Microsoft teams for testing, monitoring, etc. We have been tasked with locking down tenants to only be accessible for approved IP ranges. We allow default access to tenants from Microsoft Public IPs, which I've retrieved from a published JSON document. However, we also need to provide expanded access to tenants based on clients' needs. I'm interested in using service tags to accomplish this, by allowing clients to provide their service tags and using the tags to configure conditional access policies on behalf of the tenant. This would allow for the IP ACLs to update dynamically if the service tags are updated. Currently, conditional access policies within a tenant do not give the ability to use a service tag directly. Instead, it seems like I'll have to fetch the list of IP ranges associated with a service tag and use them to indirectly create an IP ACL, which doesn't create as dynamic of an IP ACL as using service tags would. I know that service tags can be used to create Virtual Network Security Group rules and I'm wondering if you all have any plans to allow users to create Microsoft Entra Conditional Access Policies service tags.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,599 questions
{count} votes

Accepted answer
  1. Navya 18,835 Reputation points Microsoft External Staff Moderator
    2025-05-02T19:36:59.74+00:00

    Hi @Alyssa Williams (ODSP)

    Microsoft Entra Conditional Access policies currently do not support direct use of service tags, unlike Network Security Group rules, which can reference service tags to control traffic. Instead, Conditional Access requires defining Named Locations with specific IP ranges.

    I kindly request you to share your feedback on our feedback channel: https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789

    This forum is open to the user community for upvoting and commenting. It helps our product teams effectively prioritize your request against the existing feature backlog and provides insight into the potential impact of implementing the suggested feature.

    Hope this helps. Do let us know if you any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.