Hey guys, I have ADFS 2016 in place and federated with Office 365.
Everything currently works, however it's wide open to everyone. What I need to do is restrict access to only allow users that are on the local network or are using a mobile device managed by Intune.
I've had a look at the access control policies in ADFS but I need some help as I'm not quite sure what settings to use.
I can create a rule using the "from specific network" and that gives me the option to select Intranet, Internet or specify IP ranges.
How does it know when the request comes from the "Intranet"?
I also see an option to select "from devices with specific trust level". That lets me choose from 3 options;
Authenticated, Managed or Compliant
Not sure what they all refer to, but could I use "Managed" as a way to allow mobile devices managed by Intune to get access? If you could explain what these options do would be great too.
In short, if I create the following policy would it meet my requirements:
Permit Users from Intranet network
Permit users from devices with managed trust level