Trusted Locations MFA Conditional Access not applying

Paul Ryan 21 Reputation points
2020-06-04T01:26:12.173+00:00

Hi There,

We have setup a named location in Azure Conditional Access with our organizations IP ranges in CIDR notation format so that users are not prompted for MFA when in the offices.

When looking at the users sign-in information the IP matches what we have in the named location. However when you drill down into the users policy details for our MFA policy the location is displayed as Not Satisfied.

Is there something I am missing with using named locations? We do have the same IP configured under the MFA site multi-factor authentication service settings, trusted IPs but it shouldnt matter if there is a double up correct?

Any help appreciated.

Thanks

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,466 questions
{count} votes

Accepted answer
  1. T. Kujala 8,701 Reputation points
    2020-06-04T03:55:06.443+00:00

    Verify that you have excluded the selected locations (Trusted IP ranges) from the policy. I have attached two picture.

    9038-ca.jpg9115-ca2.jpg

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Sebastian Cerazy 306 Reputation points
    2021-06-03T11:27:17.617+00:00

    Same here, wanted to move exclusively to Conditional Access Named Location (from MFA Trusted IPs), as per
    https://dirteam.com/sander/2020/07/07/todo-move-from-mfa-trusted-ips-to-conditional-access-named-locations/
    but it simply does not work, still ask for code even if I am INSIDE the IP range in Named Location

    0 comments No comments

  2. Sebastian Cerazy 306 Reputation points
    2021-07-14T17:56:55.363+00:00

    Anybody? Surely I am not the only one...?