Native Microsoft solutions in the provided context support enforcing multifactor authentication for sign-in to Microsoft 365 and Entra ID–protected resources, but they do not describe a way to require MFA specifically at Windows client (desktop) logon only when a device is offsite.
The documented strong-authentication guidance focuses on:
- Enforcing MFA for user sign-ins to cloud resources via Microsoft Entra ID and Conditional Access, using built-in or custom authentication strengths such as “Multifactor authentication strength,” “Passwordless MFA strength,” or “Phishing-resistant MFA strength”. These apply to Entra sign-ins, not to conditional Windows desktop logon based on network location.
- Using Windows Hello for Business as a strong, two-factor replacement for passwords on Windows 10/11 devices. Windows Hello for Business ties a key to the device plus a PIN or biometric, but the context does not describe a policy that turns this on only when a device is offsite.
The context also shows how MFA can be enforced broadly for all users and strengthened with passwordless or phishing-resistant methods, but it does not provide a native mechanism to scope MFA to “Windows logon only when off the corporate network.”
Based on the available documentation, there is no described native, Entra/Windows policy that enforces 2FA only for Windows sign-in when devices are offsite, without third‑party tools or additional hardware.
References: