Skip to content

Commit 82ba532

Browse files
Merge pull request #242973 from Justinha/trusted-ips
added note about CA and per-user for Trusted IPs
2 parents 7b58873 + 21733c3 commit 82ba532

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

articles/active-directory/authentication/howto-mfa-mfasettings.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: multi-factor-authentication
66
ms.service: active-directory
77
ms.subservice: authentication
88
ms.topic: how-to
9-
ms.date: 05/30/2023
9+
ms.date: 06/26/2023
1010

1111
ms.author: justinha
1212
author: justinha
@@ -257,6 +257,9 @@ If your organization uses the NPS extension to provide MFA to on-premises applic
257257

258258
Trusted IP bypass works only from inside the company intranet. If you select the **All Federated Users** option and a user signs in from outside the company intranet, the user has to authenticate by using multi-factor authentication. The process is the same even if the user presents an AD FS claim.
259259

260+
>[!NOTE]
261+
>If both per-user MFA and Conditional Access policies are configured in the tenant, you will need to add trusted IPs to the Conditional Access policy and update the MFA service settings.
262+
260263
#### User experience inside the corporate network
261264

262265
When the trusted IPs feature is disabled, multi-factor authentication is required for browser flows. App passwords are required for older rich-client applications.

0 commit comments

Comments
 (0)