Added CA210

CA210 was missing from the repo because of an export/import issue.
This commit is contained in:
j0eyv
2026-05-08 08:19:05 +02:00
parent c4de9ef351
commit 3d8c5970fa
2 changed files with 12 additions and 2 deletions
BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 84 KiB

+12 -2
View File
@@ -52,6 +52,7 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
- [CA207-Internals-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca207-internals-attacksurfacereduction-selectedapps-anyplatform-block) - [CA207-Internals-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca207-internals-attacksurfacereduction-selectedapps-anyplatform-block)
- [CA208-Internals-BaseProtection-AnyApp-MacOS-Compliant](#ca208-internals-baseprotection-anyapp-macos-compliant) - [CA208-Internals-BaseProtection-AnyApp-MacOS-Compliant](#ca208-internals-baseprotection-anyapp-macos-compliant)
- [CA209-Internals-IdentityProtection-AllApps-AnyPlatform-ContinuousAccessEvaluation](#ca209-internals-identityprotection-allapps-anyplatform-continuousaccessevaluation) - [CA209-Internals-IdentityProtection-AllApps-AnyPlatform-ContinuousAccessEvaluation](#ca209-internals-identityprotection-allapps-anyplatform-continuousaccessevaluation)
- [CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn](#ca210-internals-identityprotection-anyapp-anyplatform-block-highrisksignin)
- [CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca300-serviceaccounts-identityprotection-anyapp-anyplatform-mfa) - [CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca300-serviceaccounts-identityprotection-anyapp-anyplatform-mfa)
- [CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntrustedLocations](#ca301-serviceaccounts-attacksurfacereduction-allapps-anyplatform-blockuntrustedlocations) - [CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntrustedLocations](#ca301-serviceaccounts-attacksurfacereduction-allapps-anyplatform-blockuntrustedlocations)
- [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa) - [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa)
@@ -270,7 +271,7 @@ This policy blocks all internal users which have a **high risk** (user risk) sta
> [!IMPORTANT] > [!IMPORTANT]
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example. > Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example.
![CA201](./Images/CA201.1.png) ![CA201](./Images/CA201.png)
### CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices ### CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
@@ -321,7 +322,7 @@ This policy prevents having persistent browser sessions for internals from unman
> [!IMPORTANT] > [!IMPORTANT]
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example. > Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example.
![CA206](./Images/CA206-new.png) ![CA206](./Images/CA206.png)
### CA207-Internals-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK ### CA207-Internals-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK
@@ -353,6 +354,15 @@ This policy allows Microsoft Entra ID to re-evaluate a user's access to resource
![CA209](./Images/CA209.png) ![CA209](./Images/CA209.png)
### CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn
This policy blocks all internal users which have a **high risk** (signin risk) status, to all cloud apps, from all platforms.
> [!IMPORTANT]
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example.
![CA210](./Images/CA210.png)
### CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA ### CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA
This policy requires ServiceAccounts to use MFA, from any platform when accessing any cloud app. This policy requires ServiceAccounts to use MFA, from any platform when accessing any cloud app.