Forum Discussion
Alan Burchill
May 21, 2020Brass Contributor
MFA using Conditional Access VS Additional cloud-based MFA settings
We current have some IP Address Range exception and 14 days browser saving enabled in the "Additional cloud-based MDA Settings" will these setting work in combination with Conditional Access Policy? ...
PeterRising
May 21, 2020MVP
Alan Burchill
May 21, 2020Brass Contributor
Just to clarify, i know i can use IP address range and location in both... But if i have an IP address range configured... Are the settings additve? Or will it ignore the MFA server settings if a CA policy is applied?
- Vikram VMay 25, 2020Brass ContributorYes these 2 settings are additive. In the sense that most restrictive setting wins. If both allow, then MFA not needed. Hope this makes sense.
Also, basic MFA setting applies at tenant level, so be careful not to lock yourself out while testing it.- TheRaulMillanFeb 24, 2022Copper Contributor
Vikram V can you confirm that the rule for resolving conflicts is that the most restrictive policy wins? I was told that whatever was configured in the "Additional cloud-based MFA settings" blade had precedence over any conditional access rule.
Also, I'm trying to find the documentation for this scenario, but haven't been successful so far.
- Alan BurchillMay 25, 2020Brass Contributor
Thanks, got any reference that confirm that.... it would be helpful
- PeterRisingMay 21, 2020MVP
As far as I know, if you don't select locations options within the policy, it will use the settings defined in the standard MFA settings. If you define locations within the policy, the standard settings become irrelevant. That is my understanding. Admittedly though, I have never tested this exact scenario.