I'm hoping someone knows the secret switch that makes this happen.
We've implemented Context Aware Access (CAA) for a number of accounts, mostly to restrict usage to on-campus only. We've set up a CAA rule and applied the rule to all apps in OU's that hold those accounts and restrict access by IP address. Everything works, all apps are inaccessible.
But.
You can still login to the accounts outside of campus. You can't use any of the apps, but there's access to the account. I would have thought CAA would be able to block that as well, but apparently not.
How can I block access to accounts based on, for instance, IP address? I don't even want anyone be able to login to those accounts when not on campus.