
No-Faffing Managed IT Support & Cyber Security Support. Made in Yorkshire, built for the UK.
Jonathan Edwards, in a recent YouTube video, warns IT teams to stop treating a corporate network address as proof that a sign-in is safe. He argues that relying on a single signal such as an office IP to bypass MFA breaks the core Zero Trust principle: verify explicitly, never assume. Consequently, the video walks viewers through why that shortcut creates a real security gap and what to use instead for resilient access controls.
Edwards opens with a sharp example list of supposedly “trusted” locations to show how absurd IP-based trust can become, and then outlines the main problem: stolen credentials plus a trusted network equals an easy bypass. He then explains the practical alternative, demonstrating how to build a Conditional Access policy that requires a compliant device while still using location as one of many signals. Ultimately, his message is clear and direct: stop making the office IP the reason you skip multi-factor checks.
Many administrators keep using trusted IPs because they feel simple and predictable, and they can reduce prompts for users in a corporate location. However, Edwards points out that a single public IP often covers guest Wi‑Fi, contractors, unmanaged devices, and even compromised endpoints, so it creates a broad and inaccurate trust boundary. Therefore, what seems convenient also broadens your attack surface, because any attacker with credentials can appear to sign in from “the office.”
As Edwards notes, Microsoft’s current guidance (see Microsoft 365) favors using Conditional Access named locations and treating IPs as one risk signal rather than a bypass. In practice, legacy per-user trusted IPs do not behave the same way when Conditional Access is in place, which can lead to confusing or inconsistent behavior. Thus, administrators should define named locations in Microsoft Entra and rely on policies that combine location with device state and risk signals.
The video shows a step-by-step demo of creating a policy in Conditional Access (see Microsoft 365 Admin) that enforces device compliance instead of skipping MFA by IP alone, and Edwards emphasizes practical settings such as requiring managed devices and phishing‑resistant authentication. He recommends testing policies in audit mode, then rolling them out gradually to groups so the team can measure impact and fix gaps. Moreover, the approach combines multiple controls so that location helps inform the decision without being the deciding factor.
Transitioning away from IP-based bypasses involves tradeoffs between security and user experience, because stricter checks can increase friction for legitimate users. For example, enforcing device management requires enrollment work, which can strain help desks and require clear communication to contractors and partners. However, Edwards argues that the long-term payoff is stronger protection against credential theft and easier incident response, even though the migration demands planning and staff time.
Edwards highlights common mistakes such as keeping legacy trusted IPs enabled alongside Conditional Access, which can create unpredictable outcomes. Additionally, network address translation, mixed-use public IPs, and split VPN setups can make named locations unreliable unless administrators map and test ranges carefully. Therefore, teams must document their public ranges, validate device coverage, and monitor sign-in behavior to catch unexpected exceptions.
Good policy design blends signals — device health, user identity, location, and sign-in risk — so no single factor will expose the environment to easy compromise. Edwards suggests starting with comprehensive monitoring and then tuning Conditional Access to escalate only when risk warrants it, which preserves usability while raising assurance. Consequently, the goal is not to eliminate location checks but to make them part of a multi-dimensional decision.
The video recommends a staged rollout: build policies in a lab, pilot them with a small user group, and expand while logging and adjusting based on real-world feedback. Edwards also stresses the importance of clear change governance and user communication to avoid surprises and support tickets. Finally, he encourages regular policy reviews to adapt to new threats, network changes (see Azure DataCenter), and organizational needs.
In short, Edwards’s video serves as a practical reminder that trusting an office IP address for bypassing MFA creates an unnecessary and avoidable risk. By adopting Conditional Access named locations and enforcing compliant devices alongside strong multifactor methods, organizations can reduce that risk while maintaining a reasonable user experience. Consequently, security teams should prioritize a measured migration away from legacy trusted-IP bypasses and toward layered, testable policies.
Overall, the presentation offers a useful blend of conceptual guidance and hands-on steps, while candidly discussing tradeoffs and operational hurdles. Therefore, IT teams assessing their access rules should consider Edwards’s recommendations as part of a broader Zero Trust program that values explicit verification over assumptions.
MFA office IP risks, IP-based MFA vulnerabilities, disable trusted IP MFA, stop trusting office IPs MFA, zero trust MFA strategy, conditional access MFA policies, MFA security best practices, phishing-resistant MFA