AZURE-AD-Conditional Access

Lucy Chen 1 Reputation point
2021-07-26T23:40:18.72+00:00

Hi,

I would like to restrict access to SharePoint Online and OneDrive to a specific IP location. However, I do not want this condition to affect access to Microsoft Teams. For instance, SharePoint can only be accessed at the workplace, but Teams can be used to send and receive messages regardless of location and IP address.

Is this possible?

Thanks,

SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
9,621 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,464 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 95,181 Reputation points MVP
    2021-07-27T06:13:41.81+00:00

    You can create a CA policy that only targets SharePoint Online. Keep in mind it will still affect some Teams functionality, as Teams uses SPO/ODFB for file storage and more, but users will be able to login to Teams and use messaging/calls.


  2. Allen Xu_MSFT 13,776 Reputation points
    2021-07-27T07:32:02.637+00:00

    Hi @Lucy Chen ,

    Agree with @Vasil Michev . Here are the steps to restrict users to be allowed to access content in SharePoint and OneDrive only from specific IP addresses.

    • Access SharePoint Online admin center as a SharePoint administrator.
    • Select Policies from left-side navigation -> Access control.
    • Select Network location on the upcoming page.
      118221-image.png
    • Set Allow access only from specific IP address ranges to Yes, enter IP addresses or ranges in the textbox and click Save.

    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.