Introducing Conditional Access for the Office 365 suite!
Published Feb 04 2020 09:00 AM 53.4K Views

Howdy folks,

 

Today, I’m super excited to announce the public preview of Conditional Access for the Office 365 suite. For organizations setting policy on Office 365—such as requiring users to perform Multi-Factor Authentication (MFA) or have managed devices—of Conditional Access for the Office 365 suite makes the configuration a whole lot easier.

 

Hundreds of millions of people use the Office 365 apps like SharePoint Online, Exchange Online, and Microsoft Teams. Part of what makes these services work so well is they interact with each other and a have a collection of supporting services. There are tons of benefits of integration—one example is shared contact information in Exchange for SharePoint and Teams. In many ways, even though Office 365 is composed of many cooperating services, it functions as a single app to help your users be productive.

 

Conditional Access can be used to protect all Azure AD connected apps, including thousands of pre-integrated SaaS apps, apps your organization has developed, as well as hybrid apps accessed through the Azure Application Proxy. However, because of the close relationship between Office services it makes sense to help you target Office 365 as a single app with Azure AD Conditional Access policies. Many of you have asked for this capability, and we worked with several customers to make sure we got the feature right. 

 

Conditional Access for the Office 365 suite gives admins the option to assign policy across Office 365 with one click.  It provides consistent coverage and improves the user experience by setting a consistent policy across Office 365 apps. Assigning different policies to different services can result in unexpected interrupts as users access data that requires service to service interaction. To learn more about this topic, see our Conditional Access service dependencies documentation.

 

You can also enforce policy to apps that aren’t available in the Conditional Access app list, like the Office.com portal. See the complete list of individual apps included in the Conditional Access for the Office 365 suite. We’ll add new Office apps as they’re released, and your policies will be automatically applied.

 

How Conditional Access for the Office 365 suite works

 

Let’s take a closer look at how to use Conditional Access for the Office 365 suite.

 

You can configure Conditional Access policy in Azure AD like you normally would. When making the app assignment, select Office 365 (preview) shown below. (We put it right at the top of the list to make it easy to find.)

 

Introducing the Office 365 app for Conditional Access 1.png

When you finish setting up your policy, try running it in report-only mode. Using Conditional Access report-only mode will let you try out your policy right away and review the impact the policy will have before enabling it for your users.

 

One additional thing I’d like to note. Those of you who prefer to set different Conditional Access Policies for each Office workload can still do that.

 

Learn more about the Conditional Access for the Office 365 suite. Please try out the preview and let us know what you think in the comments below—your feedback is super valuable and greatly appreciated.

 

Best regards,

Alex Simons ( @Alex_A_Simons )

Corporate VP of Program Management

Microsoft Identity Division

 

 

 

11 Comments
Deleted
Not applicable

Is it still in preview (as shown on your screenshot)? or it is production-ready?

Copper Contributor

Do the standard conditional access licensing requirements apply?

Copper Contributor

I got excited and then realized this still requires an Azure AD premium plan. :sad:

Brass Contributor

When should we expect to see this in our tenant as it is not currently available. 

Microsoft

Hi @Deleted , 

The feature just entered public preview.

Microsoft

@NadineK , standard licensing applies applies for this. 

Microsoft

Hi @Manoj Sood , 

This should be fully enabled now. If you still aren't seeing the option you can DM on Twitter ( @caleb_b ) with your tenant ID and I'll take a look. 

Brass Contributor

@caleb_b Either I missed it previously or is showed up overnight. In either case I have it now. Based my understanding of the documentation, what I'm most interested in is the ability to put CA controls on Office.com. This has not previously been possible. Since all the other Applications in this grouping are already there own individual apps to select, Are there any plans to make Office.com be individually selectable? 

Copper Contributor

Would be great to seperate each application too.

And include MyApps portal which is currently not possible.

Brass Contributor

When we get and use this, it works fine, but we are also still trying to allow the Android outlook app and Skype and teams to work.  We have added those 3 apps to an exclusion and while it kinda works, we don't seem to be able to use the outlook android app as it comes up with a please sign in at the bottom.  When you try and sign in it gives an error.  Anyone else having this issue?

 

 

Copper Contributor

Hi Alex, it would be helpful to get some option for excluding office activations. Currently, if one needs to exclude a single app for Office desktop app activation, it is not possible. 

Version history
Last update:
‎Aug 19 2021 04:22 PM
Updated by: