Learning and Sharing
  • Home
  • Blog
  • Linux
  • macOS
  • Virtualization
    • VMware
    • VirtualBox
  • Windows
    • Windows 11
    • Windows 10
    • Windows Server
  • Series
    • Symantec
    • Intune
    • Microsoft Azure
    • Powershell
    • VirtualBox
    • VMware
    • PowerShell Learning
    • Microsoft Graph
  • More
    • Auto Installation
    • AEC Installation
  • Contact
No Result
View All Result
  • Home
  • Blog
  • Linux
  • macOS
  • Virtualization
    • VMware
    • VirtualBox
  • Windows
    • Windows 11
    • Windows 10
    • Windows Server
  • Series
    • Symantec
    • Intune
    • Microsoft Azure
    • Powershell
    • VirtualBox
    • VMware
    • PowerShell Learning
    • Microsoft Graph
  • More
    • Auto Installation
    • AEC Installation
  • Contact
No Result
View All Result
No Result
View All Result

How to Block MFA and SSPR Registrations From Untrusted Locations

July 31, 2022
in Blog, Entra ID
0
ADVERTISEMENT

Table of Contents

MultiFactor Authentication and Self Service Password Reset

When you want to enable MultiFactor Authentication and Self Service Password Reset for your users, they need to register their security settings first. Since the combined portal arrived, users can do this easily in just one place. Using this combined portal is also a requirement in order to make this possible.

And the good part is: we can control this user action with Conditional Acces. This give’s you the flexibility to limit this action to only trusted locations, or even trusted devices if you want to. Users then can only register from the locations that you marked as trusted or specific named locations.

Create a Conditional Access policy

1. Open Entra ID Conditional Access by visit https://aad.portal.azure.com/#view/Microsoft_AAD_IAM/ConditionalAccessBlade/~/Policies

2. Create a new Conditional Access policy:

  • Name: Enter a name for this policy. For example, Combined Security Info Registration on Trusted Networks.
  • Under Assignments: select Users and groups, and select the users and groups you want this policy to apply to.
Bg1337

2. Under Cloud apps or actions, select User actions, check Register security information.

Bg1338

3. Under Conditions > Locations.

  • Configure Yes.
  • Include Any location.
  • Exclude All trusted locations.
Bg1339

When you exclude all trusted locations, the policy will not apply when users register their security settings from the trusted location.

Bg1340

4. Grant: Select Block, it means when users register their security settings from outside of trusted location, the connection will be block.

Bg1379

5. Under Enable policy, select On then click Create button.

Bg1342
ADVERTISEMENT

End-user experience

From an end-user perspective, in order to register for MFA and SSPR, you would go to either:

  • https://aka.ms/setupsecurityinfo
  • https://aka.ms/mfasetup

When users do this from an untrusted location, they will see the following error.

Bg1343
5/5 - (1 vote)
Previous Post

How to Enable Require MFA for Entra ID Domain Join and Registration

Next Post

How to Join Windows 10 Devices into Azure Active Directory

Related Posts

Running Hyper-V and VMware Workstation on The Same Machine

August 15, 2024

How to Uninstall All Autodesk Products At Once Silently

July 29, 2024
Ftr5

How to Uninstall the Autodesk Genuine Service on Windows

July 29, 2024
Ftr19

How to Fix Windows Cannot Read the ProductKey From the Unattend Answer File in VirtualBox

July 26, 2024
Ftr25

How to Update Windows Terminal in Windows 10/11

July 26, 2024

How to Disable The Beep Sound in WSL Terminal on Windows

July 26, 2024

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • How To Turn On uBlock Origin Extension in Chrome (2025)
  • Images Hidden Due To Mature Content Settings In CivitAI
  • Azure OpenAI vs Azure AI Hub, How to Choose the Right One for Your Needs

Categories

Stay in Touch

Discord Server

Join the Discord server with the site members for all questions and discussions.

Telegram Community

Jump in Telegram server. Ask questions and discuss everything with the site members.

Youtube Channel

Watch more videos, learning and sharing with Leo ❤❤❤. Sharing to be better.

Newsletter

Join the movement and receive our weekly Tech related newsletter. It’s Free.

General

Microsoft Windows

Microsoft Office

VMware

VirtualBox

Technology

PowerShell

Microsoft 365

Microsoft Teams

Email Servers

Copyright 2025 © All rights Reserved. Design by Leo with ❤

No Result
View All Result
  • Home
  • Linux
  • Intune
  • macOS
  • VMware
  • VirtualBox
  • Powershell
  • Windows 10
  • Windows 11
  • Microsoft 365
  • Microsoft Azure
  • Microsoft Office
  • Active Directory

No Result
View All Result
  • Home
  • Linux
  • Intune
  • macOS
  • VMware
  • VirtualBox
  • Powershell
  • Windows 10
  • Windows 11
  • Microsoft 365
  • Microsoft Azure
  • Microsoft Office
  • Active Directory