Bypassing Azure AD MFA by adding machine IP address in MFA Trusted IPs throws error

o365developer 41 Reputation points
2020-03-09T14:27:32.127+00:00

I have added my machine's IPv4 address in MFA Trusted IPs and added CAP. But, it is not recognized and throws error.

PFA.

How to bypass Azure AD MFA by adding machine IP address in MFA Trusted IPs?
4052-opera-2020-03-06-12-44-35.jpg

4091-opera-2020-03-06-12-56-59.jpg

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,946 questions
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,346 Reputation points
    2020-03-10T07:47:33.78+00:00

    @o365developer You have added private IP Address. Azure never receives private IP address. You are required to add Public IP Address that represents your private address/subnet.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept as answer" wherever the information provided helps you to help others in the community.

    2 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Vasil Michev 97,386 Reputation points MVP
    2020-03-09T14:36:30.58+00:00

    You don't have the "Skip multi-factor authentication" checkbox ticked, without it the list of IPs you've entered does nothing really. Alternatively you can configure a location directly in CA. Apart from that, you might need to wait a bit for replication. You can always use the what-if wizard to test the policy.

    FYI, the latest version of the AAD PowerShell module will not prompt you for MFA if you have things configured correctly, I'm using pretty much the same configuration. Do note that for some other modules, using the -Credential switch leverages basic auth, so be careful with that.

    0 comments No comments

  2. o365developer 41 Reputation points
    2020-03-10T06:38:14.937+00:00

    I did tried that before posting here. It didn't work.

    Here is the screenshot of the same error after trying again. Yes, I did wait for sometime to ensure replica.

    4092-azuread.jpg

    0 comments No comments