How to block OWA externally for specific AD Group

Anonymous
2025-01-23T19:14:57+00:00

I want to share my experience configuring a special scenario to restrict OWA externally for specific AD group. (This is not to request help, it is to help others.)

Prerequisites:

Once the rules have been created within the ADFS and WAP, an Access Control Policy rule is created.

  • Which in turn consists of three different rules:

Then you add the users you want to allow or deny access from the Internet by adding them to the different groups. For internal access, OWA works without adding the users to any AD group.

It worked perfectly for me, thanks to the support of the Microsoft ADFS technician and a good friend!

Thank you so much, O.A.!

Windows Server Identity and access

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2025-01-24T06:56:17+00:00

    Hello

    Thank you for posting on the Microsoft Community.

    Thank you for sharing and for the expertise and literacy shown in this case.

    Regards

    Runjie Zhai

    0 comments No comments
  2. Anonymous
    2025-02-05T18:54:15+00:00

    Hello Runjie,

    Your welcome!

    0 comments No comments