ADFS4.0 with MFA server bypass MFA

%3CLINGO-SUB%20id%3D%22lingo-sub-777398%22%20slang%3D%22en-US%22%3EADFS4.0%20with%20MFA%20server%20bypass%20MFA%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-777398%22%20slang%3D%22en-US%22%3E%3CP%3EHello!%3C%2FP%3E%3CP%3EWe%20have%20ADFS%204.0%20and%20MFA%20Server%20and%20on%20ADFS%20side%20configured%20Access%20Control%20Policies%20and%20assigned%20to%20Office%20365%20Relying%20Party.%20I%20need%20to%20configure%20the%20following%20policy%2C%20when%20user%20belongs%20to%20security%20group%3CBR%20%2F%3E%22External%20with%20MFA%22%20and%20client%20IP%20address%20172.29.X.X%20bypass%20MFA%2C%20all%20others%20authentication%20requests%20to%20Office%20365%20for%20this%20users%20require%20MFA.%3CBR%20%2F%3EI've%20configured%20Access%20Control%20Policy%20as%20on%20picture%20but%20it's%20not%20working%2C%20always%20require%20second%20factor.%3CBR%20%2F%3EIs%20anybody%20have%20had%20such%20cases%20any%20ideas%20are%20welcomed.%3CBR%20%2F%3EThank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-777398%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eadfs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Regular Visitor

Hello!

We have ADFS 4.0 and MFA Server and on ADFS side configured Access Control Policies and assigned to Office 365 Relying Party. I need to configure the following policy, when user belongs to security group
"External with MFA" and client IP address 172.29.X.X bypass MFA, all others authentication requests to Office 365 for this users require MFA.
I've configured Access Control Policy as on picture but it's not working, always require second factor.
Is anybody have had such cases any ideas are welcomed.
Thank you!