Access Location Policy

Flavia 220 Reputation points
2023-05-26T14:00:19.9466667+00:00

Access Location Policy

Can I do a group policy in Azure AD using groups for access location restriction for Microsoft tenants? Like adding devices or users to a group to restrict locations of different parts of the world?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,217 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,665 questions
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,269 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,353 questions
{count} votes

Accepted answer
  1. Patchfox 3,806 Reputation points
    2023-05-26T16:35:08.47+00:00

    Hi, thanks for the additional information.

    If I understand you right, you need a Conditional Access rule which is limited to a specific user or device group, right?
    That's possible without AADDS (Azure Active Directory Domain Services). You only need to create a new Conditional Access rule as described in your posted doc and apply it in the configuration to a predefined AzureAD Group. The rule will be scoped on the defined group only.

    I would recommend setting the newly created rule to Report only (like WhatIf) first. And when you see that the rule works fine, you can force it.

    Consider, you need AzureAD P1 to use conditional access features.

    If you need further assistance in creating such a conditional access rule, please contact me again.


    If the reply was helpful, please don’t forget to upvote or accept it as an answer, thank you.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful