Forum Discussion
Alan Burchill
May 21, 2020Brass Contributor
MFA using Conditional Access VS Additional cloud-based MFA settings
We current have some IP Address Range exception and 14 days browser saving enabled in the "Additional cloud-based MDA Settings" will these setting work in combination with Conditional Access Policy? ...
VasilMichev
May 21, 2020MVP
If you want the IP range exclusion to take effect, you need to add "all trusted locations" condition to your CA policy, or at least the "MFA trusted IPs" location.
- PeterRisingMay 21, 2020MVP
- Alan BurchillMay 21, 2020Brass ContributorJust to clarify, i know i can use IP address range and location in both... But if i have an IP address range configured... Are the settings additve? Or will it ignore the MFA server settings if a CA policy is applied?
- Vikram VMay 25, 2020Brass ContributorYes these 2 settings are additive. In the sense that most restrictive setting wins. If both allow, then MFA not needed. Hope this makes sense.
Also, basic MFA setting applies at tenant level, so be careful not to lock yourself out while testing it.