Apr 15 2021 01:31 PM
We want to implement a CA policy which enforces MFA when users are signing in outside our trusted networks, except for MS Teams, which users should be able to Sign in to regardless of location.
We also need for ActiveSync to work.
We have configured a Policy accordingly.
In "Users and Groups" we have some users included (by Group) and others excluded (by Group)
In "Clouds app and actions" we have Include "All cloud apps" and Exclude "Microsoft Teams"
In Conditions, under Locations, we have "Any location and all trusted locations excluded"
In Conditions, under Client apps, we have Configured ("Yes") and the 2 checkboxes for "Modern authentication clients" are checked (including ActiveSync)
We have tested the Policy from an Untrusted location in Report-only mode. When logging in to Teams, the Policy is matched, despite the explicit exclusion of Teams. Reviewing the Sign In, specifically under Policy details > Assignments > Application > Microsoft Teams: we see "Matched".
In order to troubleshoot we have simplified the policy by turning Off the Client apps configuration Condition. The outcome is the same.
Additionally, we have tried adding "Office 365 Exchange Online" and "Office 365 SharePoint Online" as exclusions (together with Teams). We though this might work because there is plenty of anecdotal evidence suggesting interdependencies between these 3 Apps. However, this also has not altered the outcome.
Is there any reason that excluding Teams in a Conditional Access policy does not work as it (ostensibly) ought to?
Apr 16 2021 02:34 PM
Jan 11 2023 04:34 AM
Had the same Issue today, MS Support would neither acknowledge or deny the issue, only solution is to Exclude "Office 365" Cloud App.
For everyone that sees this, please vote for the Feedback here that this gets more awareness from MS:
Fix Conditional Access Bug, wich prevents Teams to be excluded · Community (azure.com)