Share via

Sharepoint - ID based restriction

Anonymous
2022-09-14T18:18:16+00:00

Hi,

I am trying to setup a ID-based access restriction on top of the IP-based restriction for our sharepoint sites.

To reiterate, I would like to combine those two restriction so I can restrict some users to access when they are not physically at work.

For example,

Member A can access anywhere, regardless of where he/she is; Member B is restricted to access sharepoint site if their IP address is not from work.

Would it be possible to setup both IP-based and ID-based access restriction?

If so, how can I set those up?

Microsoft 365 and Office | SharePoint | For business | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Anonymous
2022-09-14T20:37:57+00:00

Dear SEB015

Good day! Thank you for posting in Microsoft Community. We are happy to help you.

Based on your description, it seems that you want to know if you can setup both IP-based and ID-based access restriction in SharePoint site so that you can restrict some users to access when they are not physically at work.

If my understanding is correct, it's possible. As an admin, you can control access to SharePoint and OneDrive resources in Microsoft 365 based on defined network locations that you trust. This is also known as location-based policy.

Once you define the authorized IP address ranges, any user who attempts to access SharePoint and OneDrive from outside this network boundary (using web browser, desktop app, or mobile app on any device) will be blocked.

For this, follow the steps below:

For detailed information, see Control access to SharePoint and OneDrive data based on network location

And if you want to restrict SharePoint access for everyone expect for some users, you will need Azure AD conditional access policies. For an overview of conditional access in Azure AD, see Conditional access in Azure Active Directory. Please note, using this feature requires an Azure AD Premium P1 license.

For detailed information on how to create the policy, see Block access to SharePoint for specific users

Meanwhile, please remember that any IP addresses you include in Enter IP addresses or ranges" box are the ones which will be allowed, if you have added your IP address, you will have the access.

 And you should ensure you have used correct IP address, to find IP see, Find your IP address

 Valid IP address or address range values are:

  • Single IP: For example, 192.168.1.1.
  • IP range: For example, 192.168.0.1-192.168.0.254.
  • CIDR IP: For example, 192.168.0.1/25. Valid network mask values are /24 through /32.

If this is not your scenario, please kindly post back and tell us your real requirement. We’re looking forward to your reply and will continue to help you all the time!  If there are any misunderstanding or unclear, you can post back in your free time.

Your understanding and patience will be highly appreciated. I hope that you are keeping safe and well!

Sincerely,

Stacey | Microsoft Community Moderator

Was this answer helpful?

0 comments No comments

0 additional answers

Sort by: Most helpful