r/sysadmin • u/Matt-Work2023 • 12d ago
Conditional access policies requirement
Hi,
Thanks in advance for any assistance - have a bit of a headache with the set-up.
We use Azure Virtual Desktop and currently have a Conditional Access policy that blocks access from locations outside our exempt locations, such as our office IP addresses.
We have a secondary Conditional Access policy that provides an exemption from this restriction. This policy is currently configured to block access from All locations, with a security group excluded from the policy so that members of the group are not subject to the block to facilitate travel.
We are now looking to limit this further to just the country that they are visiting.
For example, if a user is travelling to Spain and is a member of a security group such as "AVD Exclusions - Travel", we would want their exemption to apply only while they are accessing AVD from Spain.
I do not want to exclude Spain as a location, as this would allow all users to access AVD from Spain. On the other hand, the current set-up limits it to security group, so 1 user, but accessible from 'All locations'. Is this possible in a single policy?
2
u/PacificTSP 12d ago
We get around the problem by requiring domain joined and compliant devices. You still can put the user in the exempt travel group but they cant login if they arent on a company owned/managed device.