Hi Jimmy,
Thanks for responding.
For your first question, so far that I know we configured the Named Locations. The Trusted IPs, I don't know exactly.
Our previous IT colleague has retired so I didn't get around to finding out about this from my previous colleague.
It is configured excluded the MFA for internal users. So if the users want to login on for example, office.com outside the organization, they must need MFA to login.
This is the Grant Settings:
The Conditional Policy is applied to this MFA group:
And when I look at Sign-in log, I see that a user was able to successfully log in to office.com without MFA. Here I see that Conditional Policy has not yet been applied?
(I just want to show you more information for understanding.
For you last question, the devices have no VPN software. Everybody must use MFA with their Smartphones.
I want to provide you more information about this, when I click on the Conditional Access Poicy Details: maybi we can understand what the issue is?