maciejrebisz.com

IT

How to get started with Conditional Access – Enable MFA on O365 web access – Mobile-First Cloud-First

maximios January 21, 2022

I started this blog post series with “How to get started with Conditional Access” and will continue with some use cases. This use cases can be combined or be implemented stand alone – it all depends what you are your organisation want to accomplish.

In this use case we just add a extra layer of security on top on Office 365 web access – that can also be other applications like sharepoint, Service Now and other apps that provided a web access through Azure Active directory. This is a typical request I get from customers – and it is a easy way to get started with Conditional Access.
The layout is to get a MFA request when:

  • Accessing Exchange Online
  • From a webbrowser
  • Outside of the corporate network
  • On any devices

Note: MFA for Office 365 requires modern authentication enabled

Start the Azure Active Directory admin center

  1. Click Azure Active Directory
  2. Click Conditional Access

  1. Enter a name that makes sense to you : “Ca – Require MFA for EXO”
  2. Select Assignments
  3. Select All users

It is recommended to do this at a test group first, and go into production in faces

  1. Select Cloud apps
  2. Select Selected apps
  3. Select Office 365 Exchange Online

  1. Select Conditions
  2. Select Device Platform
  3. Click Configure – Yes
  4. Select All platforms (Including unsupported)

If you for some reason what different rules on different OS then here is the place to select it

  1. Select Conditions
  2. Select Locations
  3. Select Configure – Yes
  4. Select Any location

If you only want the MFA to applies from outside your corporate network

  1. Select Locations
  2. Select Exclude
  3. Click Selected locations
  4. Click Select
  5. Select MFA Trusted IPs

  1. Select Conditions
  2. Select Client Apps
  3. Select Configure – Yes
  4. Select only browser

If you are not deselection “Mobile apps and desktop client” the MFA will have effect on Outlook and other mail apps as well

  1. Select Access controls
  2. Select “Require multi-factor authentication”

Now the Conditional Access rule are created and will first take effect when you sets the Enable policy to On

Now for the end user experience:

In this case my user Jane Doe start the Exchange Online web access at https://outlook.office.com/owa/

She is prompted with the normal Sign in page

Enters the password

Then the MFA kicks in and she is prompted for the text code to the authentication phone

Then she has access as normally.

It is recommended to get the end user to MFA enroll before enabling the Conditional Access policy so that you can ensure that they have access after the Conditional Access policy enforcement. When the policy is enabled the first time the end user logins in to Exchange Online webaccess they are prompted to enroll into AzureMFA – but your end users can do the in advance on this site https://aka.ms/mfasetup

Read more:

Deploy cloud-based Azure Multi-Factor Authentication If you not already have enabled modern auth in office 365 then check this out :

Enable or disable modern authentication in Exchange Online

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ Intune new Apple Enrollment admin experience and features – Mobile-First Cloud-First › How to get started with Conditional Access – Disable legacy authentication – Mobile-First Cloud-First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes