Share via

Personal Conditional Access policy

Fredrik Persson 1 Reputation point
2022-03-18T14:41:38.907+00:00

I have some Conditional Access policy's for my organization. It works fine. I know I can use "Block access by location" to for example block all logins from a specific county. 99% of the logins are made from Scandinavia. It would be a good security feature to block Africa, Asia and South America in my case. However sometimes people are there and that would cause them not be able to login. So it does not work.

However I was just doing some changes for my Visa card. In my family my card is opened in Europe, My kids are only opened in Sweden and my wifes card in some other regions. Would it not be a very good idea to have personal Conditional Access policy's that my users could manage from their account setting. I as an admin could set it for everyone and when someone travels to Japan they could just open up Japan for X days.

I do not think this works right now but maybe it is something you are working on. Or could I submit this as an feedback somewhere?

Like this:

184579-regions2.png

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,396 Reputation points Microsoft Employee Moderator
    2022-03-22T23:37:57.903+00:00

    Hi @Fredrik Persson ,

    Thank you for your post! I understand that your goal is to have personalized conditional access policies that would allow certain regions to be unblocked for a particular time range.

    At the moment, time-bound conditional access is not a feature that we have. We also do not have a way to delegate conditional access controls to other admins, as conditional access can only be configured by global administrators, security administrators, and Conditional Access administrators.

    We value this type of product feedback greatly though, and I would be happy to share this with the product team. If you would like to make a request yourself, you are also encouraged to leave feedback on the new Ideas forum, which goes directly to the product team: https://feedback.azure.com/

    I have already created a work item to capture this, but if you share more details about your scenario, I would be glad to pass include these details in the feature request.

    Thanks,

    Marilee

    -

    If this answer was helpful to you, please consider "marking as answer" so that others in the community with similar questions will more easily find the resolution.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.