Forum Discussion

Jez Blight's avatar
Jez Blight
Copper Contributor
Jun 11, 2018

Prevent users signing into O365 via browser outside of the office

Hi all,
I'm investigating securing O365 use & access, and hoping to save costs of licencing.

Is there a way, outside of buying extra licences (e.g. EMS E3) or conditional access, to prevent users signing into O365 via browser outside of the office but still allow them to work normally in the office with normal installed Office apps and services (Outlook, Onedrive, SharePoint etc.)?
The aim is to only buy extra licences for users who are approved to sign in to O365 when outside of the office.

I hope that makes sense, any advice appreciated 🙂
Thanks, Jezb

6 Replies

    • Jez Blight's avatar
      Jez Blight
      Copper Contributor
      Thanks Steve, I'll have a look at those as well. :)
    • Matthew Morgan's avatar
      Matthew Morgan
      Copper Contributor

      Strictly speaking, 'SharePoint Limited Access' requires an Azure Active Directory Premium P2 license -  see https://azure.microsoft.com/en-gb/pricing/details/active-directory/

  • If you don't want to pay for EMS, your only option is to use AD FS (or other type of federation) and configure restrictions via claims rules.

      • Brian Reid's avatar
        Brian Reid
        MVP
        You have not mentioned your company size. ADFS ideally requires multiple servers, possible in more than one site, for HA and then DR. Also with application proxies (WAP server) to protect the ADFS requests from the internet. Each of these need load balancers and Windows Server licences. One reason for needing ADFS in the past was to block legacy auth, but that has just turned up in AAD Premium 1 licences.

        So that said, maybe AADP1 licences are not as expensive as ADFS, and you get a load more with AAD than just your authentication platform.