Updated 2 weeks ago
Posted on
August 22, 2016

AzureAD Conditional Access for Office365 Exchange & SharePoint preview!!

Summary
Azure AD Conditional Access policies for Exchange Online and SharePoint Online enable admins to enforce multi-factor authentication or block access based on network location. Supported rules include always requiring MFA, requiring MFA when off-network, and blocking access entirely from untrusted locations. Microsoft recommends pairing these per-application policies with risk-based Conditional Access through Azure AD Identity Protection for layered security coverage.

Microsoft just announced the preview of Azure AD Conditional Access policies for Exchange and SharePoint Online. This option allows us to enable multi-factor authentication (MFA) or block access based on network location. These policies will only work on Exchange and Sharepoint Online. This will be helpful to improve the security of Exchange and Sharepoint.

As part of the current preview release, the following rules are supported in Exchange and SharePoint Online:

  • Always require MFA
  • Require MFA when not at work
  • Block access when not at work.

Microsoft recommends enabling these polices alongside risk based Conditional Access policy available with Azure AD Identity Protection. The risk based policies give an advanced baseline of coverage, challenging users for MFA or blocking access as risk is detected. Then apply a per-application policy, like always requiring MFA, for services with additional security or compliance requirements.

External Links:
>Know more about conditional access
>See the Microsoft Announcement

About the author

O365Reports Content Team is a specialized group of domain experts across Microsoft Entra, Exchange, SharePoint, Teams, Intune, Active Directory and security. Their work focuses on administration, governance, and configuration guidance that reflects real environment conditions. This helps IT teams apply settings correctly and maintain consistent operational control.

Previous Article

Advantage of Office 365 Groups over Traditional Distribution Groups

Next Article

Office 365 Security Analytics Service - Finding and Fixing Risk is Now Easy!