Jan 09 2020 02:34 PM
We have about 1000 E1 users that are using O365 MFA. We dont want them to receive MFA prompts when in office, only when on an external network. This can be done by the trusted IPs section in the O365 portal but it is limited to 50 IP ranges (why 50?). We have over 300 address ranges that we want to add. Is there a way to do this without giving the users EMS E3 licenses and using conditional access?
Jan 10 2020 03:07 AM
Hello@Ravindra Mathura !
Sadly no, the limit of 50 trusted IP ranges for the MFA part is not possible to work around.
Conditional Access with named locations is the way to go.
With Named locations you can use
Since you have 300 IP ranges, you will need Conditional Access with Named Locations.
Kind Regards
Oliwer Sjöberg