Issue with Conditional Access Policy for Office 365 Access on Azure VM

Aran Billen 741 Reputation points
2024-06-24T14:01:45.6333333+00:00

Certainly! Here's a refined version of your message:


Hello everyone,

I'm trying to set up a conditional access policy to allow a specific account to access Office 365 without requiring MFA when using an Azure VM. However, the policy isn't working as expected. Here's what I've done:

  1. Added the user to the conditional access policy with all apps selected.
  2. Excluded the named location of my Azure VM from the policy.
  3. Ran a What If analysis to verify the configuration, which showed it working correctly.

Despite these steps, MFA is still required when accessing Office 365 from the VM. Could anyone advise why the policy isn't taking effect as intended?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,772 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,742 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Aran Billen 741 Reputation points
    2024-06-24T14:32:18.49+00:00

    Hi,

    So here are the screenshots for more info:

    Screenshot 2024-06-24 at 15.26.18

    Screenshot 2024-06-24 at 15.26.30

    Screenshot 2024-06-24 at 15.26.43 Can you confirm how it should look as I have excluded the locations I want it not to require MFA within this policy, this same policy works for onprem IPs / devices but stuck why its not working with this VM in azure since I have got in the correct IP range which is also Matched by this policy?

    0 comments No comments

  2. Andy David - MVP 144.1K Reputation points MVP
    2024-06-24T18:26:59.4066667+00:00

    IT shouldnt be matching the location if its excluded from MFA

    If you look in the sign in logs does the location show correctly.

    IOW, if the user should be excluded from the policy, the policy should not be applied.