SOLVED
Home

Customer not looking for Azure AD Premium

%3CLINGO-SUB%20id%3D%22lingo-sub-753249%22%20slang%3D%22en-US%22%3ECustomer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-753249%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20Folks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%20I%20am%20back%20with%20a%20questionnaire%20a%20tricky%20one%20this%20time%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20scenario%20is%20based%20upon%20the%20Conditional%20Access%20for%20Location%20Based%20Access%20Control%20over%20Cloud%20Apps%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESuppose%20Customer%20is%20looking%20for%20a%20solution%20to%20block%20the%20Outlook%20(Exchange%20Online%20Only)%20Location%20wise%20where%20internal%20organisation%20will%20have%20a%20access%20of%20Exchange%20Online%20but%20outside%20organisation%20it%20must%20get%20blocked!!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENOTE%3A%20Customer%20is%20not%20looking%20for%20third%20party%20or%20Azure%20AD%20Premium%20as%20it%20is%20very%20expensive%20for%20them%20and%20also%20customer's%20only%20need%20is%20to%20block%20the%20Exchange%20online%20only%20mails%20access%20from%20outside%20the%20Organisation%20not%20any%20other%20services%20of%20O365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhether%20it%20is%20possible%20with%20O365%20itself%3F%20If%20yes%20is%20there%20any%20relevant%20document%20for%20it%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-753249%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%20Premium%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-753317%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-753317%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F136096%22%20target%3D%22_blank%22%3E%40Mitul%20Sinha%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20do%20with%20ADFS%2C%20please%20read%20more%20here%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-fs%2Foperations%2Faccess-control-policies-w2k12%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-fs%2Foperations%2Faccess-control-policies-w2k12%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20Regards%2C%3C%2FP%3E%0A%3CP%3ENuno%20%C3%81rias%20Silva%3C%2FP%3E%0A%3CP%3EMy%20Office%20365%20Essentials%20Book%20-%20%3CA%20href%3D%22https%3A%2F%2Fwww.nuno-silva.net%2Fbook-office-365-essentials%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nuno-silva.net%2Fbook-office-365-essentials%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-753364%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-753364%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Mitul%2C%3CBR%20%2F%3E%3CBR%20%2F%3EWhilst%2C%20as%20Nino%20said%2C%20you%20can%20do%20this%20with%20ADFS%20and%20it%E2%80%99s%20a%20100%25%20legitimate%20answer%20I%20wouldn%E2%80%99t%20recommend%20this%20as%20it%E2%80%99s%20likely%20to%20be%20more%20expensive%20due%20to%20the%20cost%20of%20the%20servers%20(if%20you%20want%20it%20highly%20available)%2C%20the%20added%20technical%20complexity%20and%20the%20fact%20that%20Microsoft%20no%20longer%20recommend%20ADFS%20over%20AAD%20Connect%20-%20they%20see%20it%20as%20a%20legacy%20solution.%3CBR%20%2F%3E%3CBR%20%2F%3EConditional%20access%20is%20the%20easiest%20and%20best%20way%20here.%20Typically%2C%20here%20in%20the%20UK%20it%E2%80%99s%20positioned%20that%20not%20every%20person%20in%20the%20organisation%20needs%20to%20have%20it%20so%20it%E2%80%99s%20very%20unusual%20for%20all%20to%20need%20to%20use%20an%20AAD%20premium%20licence.%20Plus%2C%20it%20is%20also%20about%20the%20other%20features%20of%20AAD%20premium%20such%20as%20application%20SSO.%20The%20organisation%20has%20to%20also%20see%20the%20cost%20of%20data%20leakage%20and%20an%20internal%20attack%20then%20will%20realise%20that%20AAD%20premium%20is%20in%20fact%20very%20cheap.%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20I%20would%20compare%20both%20the%20cost%20of%20data%20leakage%20and%20the%20cost%20of%20ADFS%20as%20Nino%20suggested%20and%20the%20AAD%20Premium%20should%20win%20out.%20Another%20potential%20option%20is%2C%20if%20they%20had%20Business%20Premium%2C%20to%20go%20to%20Microsoft%20365%20Business%20as%20Conditional%20Access%20has%20been%20added%20recently%20-%20they%20would%20get%20the%20upside%20of%20Windows%2010%20Business%20and%20Intune%20alongside%20the%20benefit%20of%20Conditional%20Access.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20terms%20of%20paying%20nothing%20at%20all%2C%20then%20they%20would%20get%20location%20based%20conditional%20access%20and%20there%20is%20no%20way%20-%20as%20far%20as%20I%20know%20to%20work%20around%20it.%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20that%20answers%20your%20question!%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%20Chris%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-753452%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-753452%22%20slang%3D%22en-US%22%3EI%20must%20say%20yes%20That's%20an%20obvious%20part%20from%20on-premises%20side%20but%20as%20customer%20is%20also%20aware%20off%20that%20it's%20hard%20to%20handle%20on-prem%20infra%20end%20so%20they%20are%20looking%20from%20O365%20perspective!!%20Is%20there%20any%20option%20where%20we%20can%20restrict%20or%20block%20Exchange%20online%20only%20-%20location%20based%20access%20control!!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-753453%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-753453%22%20slang%3D%22en-US%22%3ESo%20As%20I%20said%20yes%20option%20is%20there%20from%20ADFS%20perspective%20but%20Customer%20is%20looking%20from%20O365%20end!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-753919%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-753919%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F136096%22%20target%3D%22_blank%22%3E%40Mitul%20Sinha%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIs%20always%20advised%20to%20have%20conditional%20access%20based%20on%20Office%20365%2C%20because%20you%20do%20not%20need%20to%20maintain%20on-prem%20infrastructure.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20will%20need%20to%20compare%20costs%20and%20also%20(redundancy%20of%20servers%2C%20Internet%20connectivity%2C%20maintenance%20and%20support)%20and%26nbsp%3B%20after%20all%20you%20can%20decide%20what%20is%20the%20better%20solution%20based%20on%20costs%20and%20benefits%20of%20each%20other.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-754254%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-754254%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20it's%20only%20Exchange%20you%20want%20to%20restrict%2C%20and%20you%20don't%20want%20to%20do%20it%20via%20CA%20policies%2C%20you%20can%20take%20a%20look%20at%20using%20Client%20Access%20Rules%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fclients-and-mobile-in-exchange-online%2Fclient-access-rules%2Fclient-access-rules%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fclients-and-mobile-in-exchange-online%2Fclient-access-rules%2Fclient-access-rules%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOr%20do%20it%20via%20Claims%20rules%20on%20AD%20FS%20side.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-754398%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-754398%22%20slang%3D%22en-US%22%3EBut%20if%20the%20customer%20is%20not%20going%20to%20spend%20even%20in%20On-premises%20as%20they%20are%20looking%20the%20same%20solution%20from%20O365%20end!!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-754399%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20not%20looking%20for%20Azure%20AD%20Premium%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-754399%22%20slang%3D%22en-US%22%3EThat's%20an%20option%20which%20definitely%20gonna%20work!!%20Thank%20you%20%40vasil%20for%20the%20response!!%3C%2FLINGO-BODY%3E
Frequent Contributor

Dear Folks,

 

Here I am back with a questionnaire a tricky one this time, 

 

My scenario is based upon the Conditional Access for Location Based Access Control over Cloud Apps:

 

Suppose Customer is looking for a solution to block the Outlook (Exchange Online Only) Location wise where internal organisation will have a access of Exchange Online but outside organisation it must get blocked!!

 

NOTE: Customer is not looking for third party or Azure AD Premium as it is very expensive for them and also customer's only need is to block the Exchange online only mails access from outside the Organisation not any other services of O365.

 

Whether it is possible with O365 itself? If yes is there any relevant document for it?

 

 

8 Replies
Highlighted

Hi @Mitul Sinha,

 

You can do with ADFS, please read more here https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/access-control-policies-w2... 

 

Best Regards,

Nuno Árias Silva

My Office 365 Essentials Book - https://www.nuno-silva.net/book-office-365-essentials

Highlighted

Hi Mitul,

Whilst, as Nino said, you can do this with ADFS and it’s a 100% legitimate answer I wouldn’t recommend this as it’s likely to be more expensive due to the cost of the servers (if you want it highly available), the added technical complexity and the fact that Microsoft no longer recommend ADFS over AAD Connect - they see it as a legacy solution.

Conditional access is the easiest and best way here. Typically, here in the UK it’s positioned that not every person in the organisation needs to have it so it’s very unusual for all to need to use an AAD premium licence. Plus, it is also about the other features of AAD premium such as application SSO. The organisation has to also see the cost of data leakage and an internal attack then will realise that AAD premium is in fact very cheap.

So I would compare both the cost of data leakage and the cost of ADFS as Nino suggested and the AAD Premium should win out. Another potential option is, if they had Business Premium, to go to Microsoft 365 Business as Conditional Access has been added recently - they would get the upside of Windows 10 Business and Intune alongside the benefit of Conditional Access.

 

In terms of paying nothing at all, then they would get location based conditional access and there is no way - as far as I know to work around it.

Hope that answers your question!

Best, Chris

Highlighted
I must say yes That's an obvious part from on-premises side but as customer is also aware off that it's hard to handle on-prem infra end so they are looking from O365 perspective!! Is there any option where we can restrict or block Exchange online only - location based access control!!
Highlighted
So As I said yes option is there from ADFS perspective but Customer is looking from O365 end!
Highlighted

Hi @Mitul Sinha,

 

Is always advised to have conditional access based on Office 365, because you do not need to maintain on-prem infrastructure.

 

You will need to compare costs and also (redundancy of servers, Internet connectivity, maintenance and support) and  after all you can decide what is the better solution based on costs and benefits of each other.

Highlighted
Solution

If it's only Exchange you want to restrict, and you don't want to do it via CA policies, you can take a look at using Client Access Rules: https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/client-access-rules/...

 

Or do it via Claims rules on AD FS side.

Highlighted
But if the customer is not going to spend even in On-premises as they are looking the same solution from O365 end!!
Highlighted
That's an option which definitely gonna work!! Thank you @vasil for the response!!