Forum Discussion
MFA using Conditional Access VS Additional cloud-based MFA settings
We current have some IP Address Range exception and 14 days browser saving enabled in the "Additional cloud-based MDA Settings" will these setting work in combination with Conditional Access Policy? or will a CA Policy take precedence over these settings?
Alan
8 Replies
If you want the IP range exclusion to take effect, you need to add "all trusted locations" condition to your CA policy, or at least the "MFA trusted IPs" location.
- Alan BurchillBrass ContributorJust to clarify, i know i can use IP address range and location in both... But if i have an IP address range configured... Are the settings additve? Or will it ignore the MFA server settings if a CA policy is applied?
Hi, the Conditional Access portal allows you to browse to the Configure MFA trusted IP's as shown below;
Selecting this takes you to the MFA service settings shown below.
So you should have no issue with this. Conditional Access policies to enforce MFA will take effect even if the user has not been set to enabled for MFA, which is what CA is all about and how you want it to work.
The verification options and remember MFA options that you set should work just fine in conjunction with CA though.