introduction
in previous article we have seen how to BLOCK sales department to connect office.com from outside Saudi Arabia
this article : we will see how to require MFA ( Multi Factor Authentication ) for HR department when connecting from untrusted IP address
Pioneers OBS
before stat apply Conditional Access : we need to understand the Organization Breakdown Structure for company Pioneers OBS
company requirements
company pioneers has the following requirements
- any user from HR department who access from outside Saudi Arabia , from any platform should be registered with Multi Factor Authentication MFA
define trusted IPs
organization Pioneers101 need to trust any connection from company Public IPs >> otherwise it should be registered with MFA
the first step is to define our trusted IPs
Create Conditional Access Policy
NOW it is time to create policy to require HR department to access office 365 from outside saudi arabia using MFA
select condition access >> policies >> create policy
how policy applied
user natali@networkspioneers.com is member of HR group (please check organization OBS above )
user NAtali connect to office.com from united sta (outside Saudi Arabia ) which of course using NOT company trusted IP
let us to see whet will happened
conclusion
this article we have seen how to require group HR to access ofice.com outside with Untrusted IP with MFA
next article we will apply conditional access policy with different requirements
please be tuning