
Can I Limit Access to Office 365 For Remote or Hourly Users?
Limiting Access to Office 365 Services Based on Location
Office 365 and Exchange Online continue to use Outlook Web App, Outlook MAPI, Outlook Anywhere, and ActiveSync for client connections. Customers have expressed concerns about data loss while outside of the network and would want policies in place that limit access to Office 365 services, depending on where the client resides.
If using ADFS 2.0 for single sign on to Office 365 services, we can also enable built in client access policy features.
Client Access Policy Scenarios
Block all external access to Office 365 | Office 365 access is allowed from all clients on the internal corporate network, but requests from external clients are denied based on the IP address of the external client. |
Block all external access to Office 365, except Exchange ActiveSync | Office 365 access is allowed from all clients on the internal corporate network, as well as from any external client devices, such as smart phones, that make use of Exchange ActiveSync. All other external clients, such as those using Outlook, are blocked. |
Block all external access to Office 365, except for browser-based applications such as Outlook Web Access or SharePoint Online | Blocks external access to Office 365, except for passive (browser-based) applications such as Outlook Web Access or SharePoint Online. |
Block all external access to Office 365 for members of designated Active Directory groups. | This scenario is used for testing and validating client access policy deployment. It blocks external access to Office 365 only for members of one or more Active Directory group. It can also be used to provide external access only to members of a group. |
Using ADFS Client Access policies in conjunction with disabling Outlook cached mode will give clients full control of where their data can be accessed in any given scenario.
This posting is provided "AS IS" with no warranties, and confers no rights.

About the author
Matt Scherocman brings more than 15 years of experience in the information technology industry to Interlink. His experience includes both the system integrator and manufacturer sides of the business. During his time at the Microsoft Corporation he was responsible for all the Large Account Reseller (LAR) relationships in the four-state Heartland Area of Michigan, Ohio, Kentucky, and Tennessee. Prior to Microsoft, Scherocman led a Cincinnati -based IT consulting company to grow 5000% and become a Microsoft Worldwide Partner of the Year. He is actively involved in the strategic vision and operation decisions of the company including finance, selling strategy and marketing. Matt holds a Bachelor of Science in Business degree from Miami University and is a Certified Expert in Microsoft licensing including speaking engagements at both Microsoft's Worldwide Partner Conference and Channel Partner Summit. He is a frequent contributor to leading industry publications.
Related Posts
Welcome to the Interlink Cloud Blog
By subscribing to the blog, you will be notified whenever a new blog post is created on the site.
All content provided on this blog is for informational purposes only. The owner of this blog makes no representations or warranties regarding the information from our partners or other external sources.
Blog Categories
Blog Archive
- April 2023 (2)
- March 2023 (7)
- February 2023 (2)
- January 2023 (4)
- December 2022 (2)
- November 2022 (3)
- October 2022 (1)
- September 2022 (3)
- August 2022 (5)
- July 2022 (2)
- June 2022 (8)
- May 2022 (2)
- April 2022 (2)
- January 2022 (4)
- November 2021 (2)
- October 2021 (5)
- September 2021 (1)
- August 2021 (4)
- July 2021 (5)
- June 2021 (2)
