Situation: the client would like to restrict access to Azure administration portals to known IP addresses (their company public IP addresses) only.
Step 1: Created a Named Location.
- Login Azure portal.
- Click on Active Directory.
data:image/s3,"s3://crabby-images/4a536/4a53609517bf993e14539a2093ca84702f6e8c39" alt=""
3. Click Security on the left pane.
data:image/s3,"s3://crabby-images/d64b4/d64b43b4fc4bf7bd828d9cba372ae72a882ec386" alt=""
4. Click on Named location on the left.
data:image/s3,"s3://crabby-images/72aa9/72aa993ed725249b083a3594b4ec1236fc5e1d60" alt=""
5. Click on IP ranges Location.
data:image/s3,"s3://crabby-images/cc051/cc05122278ab26b281461d510420986140850787" alt=""
6. Enter the Name and then click on +.
data:image/s3,"s3://crabby-images/86440/86440b9dc2158993fcdfd8ae762e334acf51c140" alt=""
7. Enter the IP range you want to use and click Add.
data:image/s3,"s3://crabby-images/581ee/581ee6e9637c52429175b2fef5086800a2c54e18" alt=""
8. You can add as many IP addresses as you want. Then click Create.
data:image/s3,"s3://crabby-images/7d2c6/7d2c6e8396dc199a4f27ca781dad9a843165db90" alt=""
Step 2: Create a Conditional Access Policy
- Under Security, select Condition Access.
data:image/s3,"s3://crabby-images/57711/57711c2f316db035a3a270849bd4661d477f5808" alt=""
2. Click + New policy.
data:image/s3,"s3://crabby-images/1319a/1319a0d525faae66ad0cab5087c646783eb8e076" alt=""
3. Enter the policy name.
data:image/s3,"s3://crabby-images/e9f9a/e9f9a864456387c118dff811226dd6a2b8fe53e9" alt=""
Step 3: Modify Assignments
- Click on Users or workload identities.
data:image/s3,"s3://crabby-images/4df60/4df60f7da101dcb322c8864589fb391855566213" alt=""
Under Include, check All users.
data:image/s3,"s3://crabby-images/02455/024555e01c6553c3500842b6bd1f259edbe3c9ba" alt=""
To exclude yourself from this policy, click on Exclude. Add users or groups who will be excluded from this policy.
data:image/s3,"s3://crabby-images/bd0e5/bd0e59cad57620460de3d1336e4fbf765dbb6719" alt=""
2. Click on Cloud Apps or Action
data:image/s3,"s3://crabby-images/3c941/3c94104faee8a6c8909301826453d9ab0eebe851" alt=""
Under Cloud apps, Select apps. In our example, Microsoft Azure Management.
data:image/s3,"s3://crabby-images/55267/5526723575c76151e6a8f64bd3db0b7910de57cc" alt=""
Click on Conditions.
data:image/s3,"s3://crabby-images/97d0c/97d0c722ab601d656ab541e70f0c06e5bbfc533d" alt=""
Click on Locations.
data:image/s3,"s3://crabby-images/76c5c/76c5c65b1eda247a0229b7523ef3034c43d263d7" alt=""
Under Include, check Any Location.
data:image/s3,"s3://crabby-images/4bcd5/4bcd53d0fae3dcd9ef4596745df45f34d70294cb" alt=""
Click on Exclude, then select the IP Range you create on step 1.
data:image/s3,"s3://crabby-images/b1a58/b1a58c10fb3e90591fbb4d18c2b7cf898514be1a" alt=""
Step 4: Save and test.
data:image/s3,"s3://crabby-images/e6908/e6908b107a4e3552a47093f10a5878645c626569" alt=""