You are troubleshooting an issue where users are unable to access a sensitive application protected by a Conditional Access policy. The policy requires MFA from trusted locations, but users are reporting that they are prompted for MFA even when connecting from the corporate office, which is defined as a trusted location. What is the most likely cause?
Trap 1: The policy is configured to require MFA for all locations…
If the policy were configured to require MFA for all locations regardless of trust, then users outside the office would also be challenged, but more importantly the trusted-location condition would be ignored entirely. However, the problem description indicates the policy is intended to require MFA only from outside trusted locations, so the location condition must still be scoped to trusted locations. A misconfigured 'any location' condition would produce broad MFA prompts across all networks, not a specific failure at the corporate office. Therefore, this setting does not explain the observed issue.
Trap 2: The policy is set to 'Require MFA' instead of 'Require MFA from…
There is no separate Conditional Access grant called 'Require MFA from trusted locations'; rather, an administrator uses the Locations condition to include or exclude trusted named locations and then applies a standard 'Require MFA' grant to that scope. The description in the problem states the policy requires MFA from trusted locations, meaning the administrator already scoped the location condition correctly so trusted locations are evaluated as exempt. If the grant were simply 'Require MFA' without the location exclusion, users at the office would still be prompted but only because of the missing condition, not because of the grant control name. Since the policy description already reflects the intended location-aware behavior, this option is not the root cause.
Trap 3: Users are not assigned to the policy
If users were not assigned to the Conditional Access policy, the policy would have no effect on their sign-ins, and they would not receive an MFA challenge from this policy. The fact that users are being prompted proves they are in scope—either directly, through a group, or through all users—and the policy is being evaluated. An assignment omission would cause silent success without MFA, which is the opposite of the reported symptom. Therefore, user assignment is not the cause of the MFA prompt at the corporate office.
- A
The corporate office's public IP address is not correctly defined in the trusted location
A named location in Microsoft Entra ID must exactly match the current public egress IP range of the corporate network. If the range is stale, missing, or mistakenly configured with the wrong CIDR (for example, after an ISP change or a new NAT device), the user's source IP at the office will not match the trusted location. As a result, the Conditional Access policy sees the request as coming from an untrusted network and enforces MFA even though the user is physically inside the office. Verify the public IP and CIDR range in the named location, and confirm that the office's outbound IP has not changed.
- B
The policy is configured to require MFA for all locations regardless of trust
Why it fails: If the policy were configured to require MFA for all locations regardless of trust, then users outside the office would also be challenged, but more importantly the trusted-location condition would be ignored entirely. However, the problem description indicates the policy is intended to require MFA only from outside trusted locations, so the location condition must still be scoped to trusted locations. A misconfigured 'any location' condition would produce broad MFA prompts across all networks, not a specific failure at the corporate office. Therefore, this setting does not explain the observed issue.
- C
The policy is set to 'Require MFA' instead of 'Require MFA from trusted locations'
Why it fails: There is no separate Conditional Access grant called 'Require MFA from trusted locations'; rather, an administrator uses the Locations condition to include or exclude trusted named locations and then applies a standard 'Require MFA' grant to that scope. The description in the problem states the policy requires MFA from trusted locations, meaning the administrator already scoped the location condition correctly so trusted locations are evaluated as exempt. If the grant were simply 'Require MFA' without the location exclusion, users at the office would still be prompted but only because of the missing condition, not because of the grant control name. Since the policy description already reflects the intended location-aware behavior, this option is not the root cause.
- D
Users are not assigned to the policy
Why it fails: If users were not assigned to the Conditional Access policy, the policy would have no effect on their sign-ins, and they would not receive an MFA challenge from this policy. The fact that users are being prompted proves they are in scope—either directly, through a group, or through all users—and the policy is being evaluated. An assignment omission would cause silent success without MFA, which is the opposite of the reported symptom. Therefore, user assignment is not the cause of the MFA prompt at the corporate office.