Home

Exclude SharePoint Online from Azure Multi-factor authentication

%3CLINGO-SUB%20id%3D%22lingo-sub-870015%22%20slang%3D%22en-US%22%3EExclude%20SharePoint%20Online%20from%20Azure%20Multi-factor%20authentication%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-870015%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20setup%20a%20conditional%20access%20policy%20to%20enable%20MFA%20for%20Microsoft%20Dynamics%20365%20but%20Exclude%20SharePoint%20Online%20but%20the%20policy%20does%20not%20work%20as%20im%20prompted%20to%20enter%20the%20PIN%20for%20SharePoint%20Online.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBelow%20are%20the%20steps%20i%20have%20performed%20and%20not%20sure%20what%20I%20have%20missed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EOffice%20365%20-%20enabled%20MFA%20for%20user%20account%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20806px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F133120i0CAFC1CEE003618C%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22MFA_Enabled_Office365.JPG%22%20title%3D%22MFA_Enabled_Office365.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20922px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F133121iB5434F4C5329656D%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Include_Dynamics.JPG%22%20title%3D%22Include_Dynamics.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20479px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F133122i4B0017EFEECB11DD%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Exclude_SharePoint.JPG%22%20title%3D%22Exclude_SharePoint.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F133123iD0AE52B3167172CE%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Require_MFA.JPG%22%20title%3D%22Require_MFA.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EJag%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-870015%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%20%26amp%3B%20Compliance%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-871673%22%20slang%3D%22en-US%22%3ERe%3A%20Exclude%20SharePoint%20Online%20from%20Azure%20Multi-factor%20authentication%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-871673%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F318903%22%20target%3D%22_blank%22%3E%40jsb81%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ehave%20you%20tried%20the%20%22What%20If%22%20tool%20of%20Azure%20to%20check%20which%20CA%20policies%20apply%20to%20your%20login%20situation%3F%20Make%20sure%20there's%20no%20other%20CA%20policy%20forcing%20MFA.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-871711%22%20slang%3D%22en-US%22%3ERe%3A%20Exclude%20SharePoint%20Online%20from%20Azure%20Multi-factor%20authentication%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-871711%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F176802%22%20target%3D%22_blank%22%3E%40Tim%20Wolf%3C%2FA%3E%26nbsp%3B%20Yeah%20the%20correct%20policy%20applies%20as%20shown%20below.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F133268i712E4860888D2AE8%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22Whatif.jpg%22%20title%3D%22Whatif.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-871818%22%20slang%3D%22en-US%22%3ERe%3A%20Exclude%20SharePoint%20Online%20from%20Azure%20Multi-factor%20authentication%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-871818%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F318903%22%20target%3D%22_blank%22%3E%40jsb81%3C%2FA%3E%26nbsp%3BPlease%20choose%20Sharepoint%20Online%20and%20in%20a%20second%20screenshot%20your%20Dynamics%20app%20when%20using%20the%20What%20If%20tool.%20Currently%20you%20chose%20%22Any%20cloud%20app%22.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-871888%22%20slang%3D%22en-US%22%3ERe%3A%20Exclude%20SharePoint%20Online%20from%20Azure%20Multi-factor%20authentication%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-871888%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F176802%22%20target%3D%22_blank%22%3E%40Tim%20Wolf%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3BNo%20policy%20appears%20when%20i%20select%20SharePoint%20Online.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20by%20default%20should%20MFA%20be%20enabled%20on%20the%20user%20account%20or%20the%20conditional%20access%20Policy%20will%20enforce%20MFA%20based%20rules%20setup%20on%20the%20policy%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F133279i3C751BA5F075F071%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22WhatifSP.jpg%22%20title%3D%22WhatifSP.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-876404%22%20slang%3D%22en-US%22%3ERe%3A%20Exclude%20SharePoint%20Online%20from%20Azure%20Multi-factor%20authentication%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-876404%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F318903%22%20target%3D%22_blank%22%3E%40jsb81%3C%2FA%3E%26nbsp%3BAh.%20So%20you%20setup%20MFA%20on%20the%20user%20account%20as%20well%20as%20forcing%20it%20via%20CA%20policy%3F%20Then%20this%20is%20why%20you%20are%20prompted%20in%20SPO%20(haven't%20tested%20it%2C%20but%20makes%20sense%20to%20me).%20If%20you%20remove%20MFA%20from%20the%20user%20account%2C%20CA%20policy%20will%20force%20MFA%20only%20on%20the%20conditions%20you%20chose.%3C%2FP%3E%3C%2FLINGO-BODY%3E
jsb81
Occasional Contributor

Hi All,

 

I have setup a conditional access policy to enable MFA for Microsoft Dynamics 365 but Exclude SharePoint Online but the policy does not work as im prompted to enter the PIN for SharePoint Online.

 

Below are the steps i have performed and not sure what I have missed.

 

Office 365 - enabled MFA for user account

MFA_Enabled_Office365.JPG

 

Include_Dynamics.JPG

 

Exclude_SharePoint.JPG

 

Require_MFA.JPG

 

Thanks

Jag

5 Replies

Hi @jsb81,

 

have you tried the "What If" tool of Azure to check which CA policies apply to your login situation? Make sure there's no other CA policy forcing MFA.

@Tim Wolf  Yeah the correct policy applies as shown below.

 

Whatif.jpg

@jsb81 Please choose Sharepoint Online and in a second screenshot your Dynamics app when using the What If tool. Currently you chose "Any cloud app".

@Tim Wolf 

 No policy appears when i select SharePoint Online. 

 

So by default should MFA be enabled on the user account or the conditional access Policy will enforce MFA based rules setup on the policy?

 

WhatifSP.jpg

@jsb81 Ah. So you setup MFA on the user account as well as forcing it via CA policy? Then this is why you are prompted in SPO (haven't tested it, but makes sense to me). If you remove MFA from the user account, CA policy will force MFA only on the conditions you chose.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies