Forum Discussion

Jay2theJay's avatar
Jay2theJay
Copper Contributor
Jul 22, 2021

Conditional Access - Limit all access to trusted location except teams

Goal:
For all accounts in a named group
Block access to everything unless connecting from trusted IP locations eg the office IP
Caveat, Teams is available to any IP address

 

We have a working conditional access policy that restricts access for a named group, so that they are blocked to all applications, unless connecting from specific IP addresses. 

We would like to enable access to Teams (either web or client) from any location.  Therefore we think the best solution would be to exclude Teams from this policy.

 

I've read that it isn't possible to exclude teams without excluding SharePoint, so I've excluded teams and Office 365 using the list of excluded apps, this works as intended, but excluding "Office 365" allows access to all O365 applications and therefore defeats the purpose of the policy.

Is it possible to exclude Teams and the minimum number of other applications that teams access requires to acheive my goal?