Howdy, Great news today! The Azure AD Conditional Access per app MFA and and Network Location policies are GA! We have seen incredible demand for these capabilities from customers so I'm completely stoked that they are ready for broad production use! Of note, quite a few customers of the customers we've been working directly with in public preview are already using these policies in the production environment and getting a ton of value from them. The Conditional Access policy engine is built to allow admins maintain control in a cloud-first, mobile-first world. Conditional Access policy evaluation can be based on device health, MFA, location and detected risk. You can learn more about Conditional Access here . Today's announcement moves the features currently in the Conditional Access public preview to GA, enabling the following policies to be set per-application:
- Always require MFA
- Require MFA when not at work
- Block access when not at work.
- Microsoft Office 365 Exchange Online
- Microsoft Office 365 SharePoint Online
- Dynamics CRM
- Microsoft Office 365 Yammer
- All of the 2,600+ SaaS applications from the Azure AD application gallery
- On-premises app registered with Azure AD Application Proxy
- LOB apps registered with Azure AD.
Many Customers are already using MFA and Location rules
Over the last few months, we've been working closely with our early adopter customers and Microsoft's own IT department to help them deploy Conditional Access in production. We've received a ton of positive feedback from them on how the extra security provided by these policies gave them the confidence to accelerate their adoption of cloud services:Conditional access gave us the ability to deliver a positive user experience while providing a secure solution tightly integrated with our existing Microsoft platform Office 365, Azure Application Proxy, and Azure AD SaaS applications
- Unilever
Using Azure AD conditional access policy for Onedrive, SharePoint and Exchange online, we were able to adopt Office 365, while protecting critical company data, choosing which groups of users would have access to which applications and from which locations
-Orbotech
Conditional access gave Microsoft IT the granularity we needed to tightly control our rollout of MFA for email. Being able to tightly coordinate the technical deployment with our internal communication/education program was key to delivering a great user experience and more security.
- Microsoft IT
We love to see the value this is bringing to organizations, and are excited to make it available to all our customers!