Skip to Content
Communication Square LLC Help Center

How to Setup MFA Conditional Access in Azure AD

Written April 2018. Microsoft changes these admin screens often, so the screenshots below may not match what you see today. The sequence of steps is usually still correct — if something looks wrong, tell us and we'll update it.

To Configure your Conditional Access Policy

In the Azure portal, on the left navbar, click  Azure Active Directory.

  1. On the Azure Active Directory blade, in the Manage section, click Conditional access
  2. On the Conditional Access blade, to open the New blade, in the toolbar on the top, click Add.
  3. On the New blade, in the Name textbox, type a name for your policy.
  4. In the Assignment section, click Users and groups.
  5. On the Users and groups blade, perform the following steps:

a. Click  Select users and groups.

b. Click  Select.

c. On the  Select blade, select your test user, and then click Select.

d. On the  Users and groups blade, click Done.

  1. On the New blade, to open the Cloud apps blade, in the Assignment section, click Cloud apps.
  2. On the Cloud apps blade, perform the following steps:

a. Click  Select apps.

b. Click  Select.

c. On the  Select blade, select your cloud app, and then click Select.

d. On the  Cloud apps blade, click Done.

  1. On the New blade, to open the Conditions blade, in the Assignment section, click Conditions.
  2. On the Conditions blade, to open the Locations blade, click Locations.
  3. On the Locations blade, perform the following steps:

a. Under  Configure, click Yes.

b. Under  Include, click All locations.

c. Click  Exclude, and then click All trusted IPs.

d. Click  Done.

  1. On the Conditions blade, click Done.On the New blade, to open the Grant blade, in the Controls section, click Grant.
  2. On the Grant blade, perform the following steps:

a. Select  Require multi-factor authentication.

b. Click  Select.

  1. On the New blade, under Enable policy, click On.
  2. On the New blade, click Create.

Reference Link:

https://docs.microsoft.com/en-us/azure/active-directory/active-directory-conditional-access-azure-portal-get-started

Last updated on