How to block access to Sign on (O365 Cloud Apps Exchange, SharePoint, Teams) while on Private VPN or anonymous Proxy

Bearded Techie 0 Reputation points
2025-05-13T19:49:04.3233333+00:00

I am attempting to setup a Conditional Access policy that will block access to all Microsoft services if the users are utilizing any of the unsanctioned VPN services in Windows Defender Cloud App Catalog.

The policies in Defender seem to only create a notification.

I was following along with this article from Tatu Seppala https://www.linkedin.com/pulse/blocking-sign-ins-from-tor-other-anonymous-proxies-365-tatu-sepp%C3%A4l%C3%A4

The idea is Conditional Access App Control and Defender for Cloud App Access Policy. The problem is that when I create the Access Control policy, I get an error that says I do not have any apps deployed. User's image

So what is the best way to stop access to all of my Office 365 services if a user is using a private VPN service like ExpressVPN, NordVPN, or any other Anonymous Proxy service when I don't have an app to deploy?

For reference: Azure, Intune, Entra, Defender, and Defender with Cloud Apps are all in play. We already have GeoIP locations blocked so anyone outside of the country fails to get access, unless they have an exception or a private VPN service in play. We need to stop the VPN service unless it is the one our company provides.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.