Restricting Security Info Registration to Trusted Locations
The Register Security Info Only From Trusted Locations template makes a user prove themselves more strongly when they register or change their MFA methods from somewhere the customer does not control. It closes a specific attack: an adversary who already has the password registers their own authenticator and takes the account over for good.
This guide covers the whole job: create the trusted location, deploy the policy against it, review the report-only results, then enforce.
What you need. The Manage permission on Secure, a selected customer with a healthy Microsoft 365 integration, and the customer's public egress IP addresses.
This is not a device-enrolment policy. It governs the register security information user action — adding or changing an authenticator, phone number or other MFA method. To require managed hardware for that action instead of a trusted location, use the Register MFA from Managed Devices template.
