Skip to main content

Traveling Internationally

Add and remove people to the "Traveling Internationally" Security Group when they are going outside of North America on a trip. We have a conditional policy setup that blocks any sign in attempts coming from locations outside of the United States, Canada, and Mexico. Adding to the group will let a person bypass the location block set in place from the conditional policy. 

We excluded the DirSync admin account as a backup account so that we aren't locked out of the Tenant.

image.png

Settings are in Azure Conditional Access Policy here: https://portal.azure.com/#blade/Microsoft_AAD_ConditionalAccess/PolicyBlade/policyId/61826f26-b29d-4032-9de7-40c765d588b9/appId//policyName//preConfiguredPolicy/