How to Configure OneDrive IP and Location Restrictions in Entra
Question details
The user wants to establish IP address and location restrictions for OneDrive using Microsoft Entra Conditional Access without accidentally locking out administrative access.

- Product
- Microsoft Entra, OneDrive
- Device & OS
- not provided
- Scenario
- Configuring network-based conditional access policies to secure enterprise cloud storage access.
- Observed behavior
- Administrators need to restrict access by trusted locations but are concerned that incorrect settings in Conditional Access could lead to a total tenant lockout.
Ensure you have Conditional Access Administrator privileges and have created a separate emergency 'break-glass' admin account that is excluded from all policies to prevent accidental tenant lockouts.
Set Up Location Restrictions in Microsoft Entra
Create and safely test a Conditional Access policy in Microsoft Entra targeting OneDrive access based on trusted network locations.
This method involves defining your trusted outbound IP addresses and using them to filter access to Office 365 services, which inherently includes SharePoint and OneDrive.
Log in to the Microsoft Entra admin center, navigate to Protection > Conditional Access, and select 'Named locations' to add your organization's public IP ranges.
Go to 'Policies', click 'New policy', and assign it to your target users while strictly excluding your emergency administrator account.
Under 'Target resources', select 'Cloud apps' and choose 'Office 365' or 'SharePoint' to ensure OneDrive is covered by the restriction.
Under 'Conditions', go to 'Locations', include 'Any location', and explicitly exclude the trusted named locations you defined earlier.
Under 'Access controls', set the policy to 'Block access'. Critically, change the policy state at the bottom to 'Report-only' to test its impact before fully enabling it.

Consult Microsoft Q&A for Complex Routing
For advanced Microsoft Intune integration or complex Conditional Access problems, utilize the official Microsoft Q&A forums.
Experience a Seamless and Secure Office Alternative
While Microsoft Entra handles complex enterprise security policies for cloud storage like OneDrive, your everyday document editing should remain fast and uncomplicated. WPS Office provides a lightweight, highly compatible alternative for creating and editing documents securely.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install the Suite: Run the installer and follow the on-screen prompts to set up WPS Office on your device in minutes.
- 3. Edit Your Documents: Open your existing Microsoft Office files directly in WPS Office and start editing with full format compatibility.

Frequently Asked Questions
Why am I locked out of Microsoft Entra after configuring a Conditional Access policy?
This occurs if a policy blocks all access without excluding a trusted IP address or an emergency administrator account. If you lack a 'break-glass' account, you may need to contact Microsoft Support to regain tenant access.
Can I restrict OneDrive access to specific devices instead of IP addresses?
Yes. Microsoft Entra allows you to use device filters in Conditional Access policies to restrict access based on compliance status, domain-join state, or specific device attributes rather than just geographical or IP locations.
What is 'Report-only' mode in Conditional Access?
Report-only mode allows administrators to evaluate the impact of a new Conditional Access policy during actual user sign-ins without enforcing the block or grant controls, helping to identify potential misconfigurations safely.
Does a Conditional Access policy apply to the OneDrive desktop sync client?
Yes. Conditional Access policies targeting Office 365 or SharePoint apply to both web browser access and desktop sync clients, meaning users outside trusted locations will lose file synchronization capabilities.




