A cloud-based identity and access management service for securing user authentication and resource access
notifications for Outlook and Teams in conditional access control for mobile devices (iOS, Android)
Regarding notifications for Outlook and Teams in conditional access control for mobile devices (iOS, Android), could you please clarify the following two points?
- If conditional access is configured to grant access based on location (global IP), is it possible to ensure that notifications are still received on mobile devices even if the global IP changes?
- If so, what are the steps involved (e.g., configuring notification-related apps as exceptions to access control for the target resource)?
As background, we have implemented conditional access to M365 based on global IP.
Currently, we do not apply policies to mobile devices, but we are considering doing so.
We plan to install a VPN client on mobile devices to ensure they can connect even when subject to global IP controls; however, since the VPN client is not designed for a constant connection, we anticipate that the global IP will change to an unauthorized one when the connection is lost.
While it is acceptable to require a VPN connection when using Outlook or Teams,
we would like notifications to continue being delivered even when the connection is lost.