Conditional Access

david wrafter 126 Reputation points
2022-03-23T08:43:06.72+00:00

Hi Q&A

I have written a Conditional Access policy. I have set an IP range in the Named Location section of the Security section in Azure Active Directory on my Azure tenancy. I have added the trusted location which contains
the IP range to the location section of a Conditional Access policy. I am testing the Conditional Access policy from a laptop outside the IP Range specified in the Conditional Access policy. When I login to the Azure portal from a laptop outside the IP Range specified in the Conditional Access policy I can log into the Azure portal successfully. When I view the Conditional Access section of the users sign in section of Active Directory the Conditional Access section states 'Location' not matched. Any ideas on how I can get policy to work and force denial of login using the location Condition in the Conditional access policy?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,065 questions
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,646 Reputation points
    2022-03-23T13:42:41.203+00:00

    Hi @david wrafter • Thank you for reaching out.

    From your question I understood that you want to allow sign-ins only from the location that you have added to the Conditional Access policy and restrict access from all other locations.

    In order to achieve this, you need to create a conditional access policy with the below conditions:

    1. In the conditional access policy, navigate to Conditions > Locations > Include "Any location" and Exclude "Your Named Location", as shown below:
      186046-image.png
    2. Then go to Access Control section > Grant > Block access.
      186152-image.png

    With this configuration, all the locations will be in the scope of the policy and will be blocked but the locations under the exclusion list will not be blocked and the sign-ins will be allowed from those locations.

    Currently, if you have included a specific location in the CA Policy and signing-in from another location, the conditional access policy will not be applied as the location condition is not meeting.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


1 additional answer

Sort by: Most helpful
  1. david wrafter 126 Reputation points
    2022-03-25T08:56:26.247+00:00

    Thank you for your help Aman preetsingh. Much appreciated!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.