How to: Require MFA for access from untrusted networks with Conditional Access

Azure Active Directory (Azure AD) enables single sign-on to devices, apps, and services from anywhere. Your users can access your cloud apps not only from your organization's network, but also from any untrusted Internet location. A common best practice for access from untrusted networks is to require multi-factor authentication (MFA).

This article gives you the information you need to configure a Conditional Access policy that requires MFA for access from untrusted networks.


This article assumes that you are familiar with the basic concepts of Conditional Access.

Scenario description

To master the balance between security and productivity, it might be sufficient for you to only require a password for sign-ins from your organization's network. However, for access from an untrusted network location, there is an increased risk that sign-ins are not performed by legitimate users. To address this concern, you can block access from untrusted networks. Alternatively, you can also require multi-factor authentication (MFA) to gain back additional assurance that an attempt was made by the legitimate owner of the account.

With Azure AD Conditional Access, you can address this requirement with a single policy that grants access:

  • To selected cloud apps
  • For selected users and groups
  • Requiring multi-factor authentication
  • When access is originated from:
    • A location that is not trusted


The challenge of this scenario is to translate access from an untrusted network location into a Conditional Access condition. In a Conditional Access policy, you can configure the locations condition to address scenarios that are related to network locations. The locations condition enables you to select named locations, which are logical groupings of IP address ranges, countries and regions.

Typically, your organization owns one or more address ranges, for example, - You can configure a named location by:

  • Specifying this range (
  • Assigning a descriptive name such as Corporate Network

Instead of trying to define what all locations are that are not trusted, you can:

  • Include any location

    Screenshot of the Azure A D Locations pane, with Configure set to Yes, the Include tab visible, and the Any location option selected and highlighted.

  • Exclude all trusted locations

    Screenshot of the Azure A D Locations pane, with Configure set to Yes, the Exclude tab visible, and the All trusted locations option selected.

Policy deployment

With the approach outlined in this article, you can now configure a Conditional Access policy for untrusted locations. To make sure that your policy works as expected, the recommended best practice is to test it before rolling it out into production. Ideally, use a test tenant to verify whether your new policy works as intended.

Next steps

If you would like to learn more about Conditional Access, see What is Conditional Access in Azure Active Directory?