From 4bf954b7d380ac93e0996204fca2e388971eda36 Mon Sep 17 00:00:00 2001 From: j0eyv <41282854+j0eyv@users.noreply.github.com> Date: Tue, 9 Apr 2024 15:46:32 +0200 Subject: [PATCH] Create README.md --- README.md | 2045 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 2045 insertions(+) create mode 100644 README.md diff --git a/README.md b/README.md new file mode 100644 index 0000000..cba5287 --- /dev/null +++ b/README.md @@ -0,0 +1,2045 @@ + +# Intune documentation + + +*Organization:* m365jv + +*Generated by:* Joey Verlinden (Access@m365jv.onmicrosoft.com) + +*Generated:* 09/04/2024 15:43:22 + + +## Table of Contents +- [Conditional access](#section-1) + + - [Conditional access policies](#section-2) + + - [CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-3) + + - [CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist](#section-4) + + - [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#section-5) + + - [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#section-6) + + - [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#section-7) + + - [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload](#section-8) + + - [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#section-9) + + - [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-10) + + - [CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#section-11) + + - [CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-12) + + - [CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk](#section-13) + + - [CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices](#section-14) + + - [CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA](#section-15) + + - [CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms](#section-16) + + - [CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration](#section-17) + + - [CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ](#section-18) + + - [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-19) + + - [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#section-20) + + - [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#section-21) + + - [Named Locations](#section-22) + + - [ALLOWED COUNTRIES](#section-23) + + +

Conditional access

+

Conditional access policies

+

CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:47:07
Last modifiedWednesday, 27 March 2024 14:41:39
+ +###### Table 1. Basics - CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeAll users
Exclude
Directory rolesDirectory Synchronization Accounts
Users and groups
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
+ +###### Table 2. Settings - CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA + + +

CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 08:02:06
Last modifiedTuesday, 2 January 2024 10:38:04
+ +###### Table 3. Basics - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Locations
IncludeAny location
ExcludeALLOWED COUNTRIES
Grant
Control access enforcement to block or grant access.Block access
+ +###### Table 4. Settings - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist + + +

CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:08:14
Last modifiedTuesday, 2 January 2024 10:38:10
+ +###### Table 5. Basics - CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Client apps
IncludeExchange ActiveSync
Other clients
Grant
Control access enforcement to block or grant access.Block access
+ +###### Table 6. Settings - CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication + + +

CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA

+ + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 3 January 2024 07:52:15
+ +###### Table 7. Basics - CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA - Exclude
Cloud apps or actions
User actions
Select the action this policy will apply toRegister or join devices
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
+ +###### Table 8. Settings - CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA + + +

CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 27 March 2024 14:28:00
Last modifiedMonday, 8 April 2024 12:38:51
+ +###### Table 9. Basics - CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Block access
+ +###### Table 10. Settings - CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows + + +

CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 27 March 2024 14:40:41
Last modifiedMonday, 8 April 2024 12:38:39
+ +###### Table 11. Basics - CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeOffice 365 Exchange Online
Office 365 SharePoint Online
Conditions
Client apps
IncludeBrowser
Filter for devices
Exclude filtered devices from policydevice.isCompliant -eq True
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Use app enforced restrictionsEnabled
+ +###### Table 12. Settings - CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload + + +

CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedFriday, 22 December 2023 10:12:23
Last modifiedWednesday, 3 January 2024 09:43:35
+ +###### Table 13. Basics - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Directory roles
Global Administrator
Security Administrator
SharePoint Administrator
Exchange Administrator
Conditional Access Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Application Administrator
Cloud Application Administrator
Password Administrator
Privileged Authentication Administrator
Privileged Role Administrator
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeMicrosoftAdminPortals
Grant
Control access enforcement to block or grant access.Grant access
Authentication strength
For multiple controlsRequire one of the selected controls
+ +###### Table 14. Settings - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA + + +

CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedMonday, 31 January 2022 16:44:43
Last modifiedTuesday, 2 January 2024 10:38:19
+ +###### Table 15. Basics - CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Directory roles
Exchange Administrator
Security Administrator
Conditional Access Administrator
SharePoint Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Global Administrator
Global Reader
Intune Administrator
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Locations
IncludeAny location
Client apps
IncludeExchange ActiveSync
Browser
Mobile apps and desktop clients
Other clients
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
+ +###### Table 16. Settings - CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA + + +

CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 10:02:19
Last modifiedTuesday, 2 January 2024 10:38:23
+ +###### Table 17. Basics - CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Directory roles
Authentication Administrator
Billing Administrator
Conditional Access Administrator
Exchange Administrator
Global Administrator
Global Reader
Helpdesk Administrator
Intune Administrator
Security Administrator
User Administrator
SharePoint Administrator
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Sign-in frequency12 hours
+ +###### Table 18. Settings - CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency + + +

CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedMonday, 31 January 2022 16:44:44
Last modifiedTuesday, 2 January 2024 14:10:23
+ +###### Table 19. Basics - CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Locations
IncludeAny location
Client apps
IncludeBrowser
Mobile apps and desktop clients
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
+ +###### Table 20. Settings - CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA + + +

CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:45:42
Last modifiedWednesday, 24 January 2024 08:53:55
+ +###### Table 21. Basics - CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
User risk
IncludeHigh
Sign-in risk
IncludeHigh
Grant
Control access enforcement to block or grant access.Block access
+ +###### Table 22. Settings - CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk + + +

CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 10:06:50
Last modifiedWednesday, 3 January 2024 09:54:21
+ +###### Table 23. Basics - CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Device platform
IncludeWindows
macOS
Filter for devices
Exclude filtered devices from policydevice.deviceOwnership -eq "Company" -or device.isCompliant -eq True
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Sign-in frequency12 hours
+ +###### Table 24. Settings - CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices + + +

CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:30:47
Last modifiedTuesday, 2 January 2024 10:39:07
+ +###### Table 25. Basics - CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeMicrosoft Intune Enrollment
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
Session
Sign-in frequencyEvery time
+ +###### Table 26. Settings - CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA + + +

CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:32:55
Last modifiedTuesday, 2 January 2024 10:39:24
+ +###### Table 27. Basics - CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Device platform
IncludeAny device
ExcludeAndroid
iOS
Windows
macOS
Grant
Control access enforcement to block or grant access.Block access
+ +###### Table 28. Settings - CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms + + +

CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration

+ + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 3 January 2024 08:08:24
+ +###### Table 29. Basics - CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration - Exclude
Cloud apps or actions
Cloud apps
IncludeNone
Grant
Control access enforcement to block or grant access.Grant access
Require device to be marked as compliantEnabled
Require Microsoft Entra hybrid joined deviceEnabled
For multiple controlsRequire one of the selected controls
+ +###### Table 30. Settings - CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration + + +

CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:27:49
Last modifiedWednesday, 3 January 2024 09:52:28
+ +###### Table 31. Basics - CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
ExcludeMicrosoft Intune Enrollment
Conditions
Device platform
IncludeWindows
Grant
Control access enforcement to block or grant access.Grant access
Require device to be marked as compliantEnabled
Require Microsoft Entra hybrid joined deviceEnabled
For multiple controlsRequire one of the selected controls
+ +###### Table 32. Settings - CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ + + +

CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:23:41
Last modifiedTuesday, 2 January 2024 10:52:19
+ +###### Table 33. Basics - CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
+ +###### Table 34. Settings - CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA + + +

CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:37:47
Last modifiedWednesday, 27 March 2024 15:06:48
+ +###### Table 35. Basics - CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Exclude
Users and groupsCA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
ExcludeMy Apps
Office365
Grant
Control access enforcement to block or grant access.Block access
+ +###### Table 36. Settings - CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess + + +

CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameCA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:55:02
Last modifiedTuesday, 2 January 2024 10:39:39
+ +###### Table 37. Basics - CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Users and groups
Include
IncludeSelect users and groups
Exclude
Users and groupsCA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Sign-in frequency12 hours
+ +###### Table 38. Settings - CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency + + +

Named Locations

+

ALLOWED COUNTRIES

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
NameValue
Basics
NameALLOWED COUNTRIES
Description
Profile typeNamed locations
CreatedWednesday, 7 September 2022 13:48:18
Last modifiedFriday, 3 February 2023 08:18:30
+ +###### Table 39. Basics - ALLOWED COUNTRIES + + + + + + + + + + + + + + + + + + + +
NameValue
Country lookup methodDetermine location by IP address (IPv4 and IPv6)
Include unknown countries/regionsDisabled
Countries

+ +###### Table 40. Settings - ALLOWED COUNTRIES + + +