logo
search
Conditional Access Problems

How to Configure OneDrive IP and Location Restrictions in Entra

Maira MehtabMaira Mehtab Sep 28, 2026 868 views

Question details

The user wants to establish IP address and location restrictions for OneDrive using Microsoft Entra Conditional Access without accidentally locking out administrative access.

How to Configure OneDrive IP and Location Restrictions
Product
Microsoft Entra, OneDrive
Device & OS
not provided
Scenario
Configuring network-based conditional access policies to secure enterprise cloud storage access.
Observed behavior
Administrators need to restrict access by trusted locations but are concerned that incorrect settings in Conditional Access could lead to a total tenant lockout.
Before you start

Ensure you have Conditional Access Administrator privileges and have created a separate emergency 'break-glass' admin account that is excluded from all policies to prevent accidental tenant lockouts.

Solution 1Recommended

Set Up Location Restrictions in Microsoft Entra

Create and safely test a Conditional Access policy in Microsoft Entra targeting OneDrive access based on trusted network locations.

This method involves defining your trusted outbound IP addresses and using them to filter access to Office 365 services, which inherently includes SharePoint and OneDrive.

1
Define Trusted Locations

Log in to the Microsoft Entra admin center, navigate to Protection > Conditional Access, and select 'Named locations' to add your organization's public IP ranges.

2
Create a New Policy

Go to 'Policies', click 'New policy', and assign it to your target users while strictly excluding your emergency administrator account.

3
Target OneDrive Resources

Under 'Target resources', select 'Cloud apps' and choose 'Office 365' or 'SharePoint' to ensure OneDrive is covered by the restriction.

4
Configure Location Conditions

Under 'Conditions', go to 'Locations', include 'Any location', and explicitly exclude the trusted named locations you defined earlier.

5
Set Access Controls and Test

Under 'Access controls', set the policy to 'Block access'. Critically, change the policy state at the bottom to 'Report-only' to test its impact before fully enabling it.

Set Up Location Restrictions in Microsoft Entra
Safe Deployment: Testing the policy with a pilot user group in Report-only mode allows you to verify that valid OneDrive traffic isn't blocked before enforcing it tenant-wide.
Free Microsoft Office alternative

Experience a Seamless and Secure Office Alternative

While Microsoft Entra handles complex enterprise security policies for cloud storage like OneDrive, your everyday document editing should remain fast and uncomplicated. WPS Office provides a lightweight, highly compatible alternative for creating and editing documents securely.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install the Suite: Run the installer and follow the on-screen prompts to set up WPS Office on your device in minutes.
  3. 3. Edit Your Documents: Open your existing Microsoft Office files directly in WPS Office and start editing with full format compatibility.
Fully compatible with Microsoft Office formats including Word, Excel, and PowerPoint.Built-in cloud integration for secure and seamless document synchronization across devices.Lightweight installation with an intuitive, familiar tabbed interface for instant productivity.Completely free basic features with robust PDF editing and conversion tools.
microsoft office alternative - wps office

Frequently Asked Questions

Why am I locked out of Microsoft Entra after configuring a Conditional Access policy?

This occurs if a policy blocks all access without excluding a trusted IP address or an emergency administrator account. If you lack a 'break-glass' account, you may need to contact Microsoft Support to regain tenant access.

Can I restrict OneDrive access to specific devices instead of IP addresses?

Yes. Microsoft Entra allows you to use device filters in Conditional Access policies to restrict access based on compliance status, domain-join state, or specific device attributes rather than just geographical or IP locations.

What is 'Report-only' mode in Conditional Access?

Report-only mode allows administrators to evaluate the impact of a new Conditional Access policy during actual user sign-ins without enforcing the block or grant controls, helping to identify potential misconfigurations safely.

Does a Conditional Access policy apply to the OneDrive desktop sync client?

Yes. Conditional Access policies targeting Office 365 or SharePoint apply to both web browser access and desktop sync clients, meaning users outside trusted locations will lose file synchronization capabilities.