diff --git a/Images/CA000.png b/Images/CA000.png new file mode 100644 index 0000000..5901037 Binary files /dev/null and b/Images/CA000.png differ diff --git a/Images/CA001.png b/Images/CA001.png new file mode 100644 index 0000000..1a21675 Binary files /dev/null and b/Images/CA001.png differ diff --git a/Images/CA002.png b/Images/CA002.png new file mode 100644 index 0000000..2a44d21 Binary files /dev/null and b/Images/CA002.png differ diff --git a/Images/CA003.png b/Images/CA003.png new file mode 100644 index 0000000..9a9b3e2 Binary files /dev/null and b/Images/CA003.png differ diff --git a/Images/CA004.png b/Images/CA004.png new file mode 100644 index 0000000..7d0fe94 Binary files /dev/null and b/Images/CA004.png differ diff --git a/Images/CA005.png b/Images/CA005.png new file mode 100644 index 0000000..1a82d95 Binary files /dev/null and b/Images/CA005.png differ diff --git a/Images/CA100.png b/Images/CA100.png new file mode 100644 index 0000000..b54a63e Binary files /dev/null and b/Images/CA100.png differ diff --git a/Images/CA101.png b/Images/CA101.png new file mode 100644 index 0000000..6ce4541 Binary files /dev/null and b/Images/CA101.png differ diff --git a/Images/CA102.png b/Images/CA102.png new file mode 100644 index 0000000..316485a Binary files /dev/null and b/Images/CA102.png differ diff --git a/Images/CA200.png b/Images/CA200.png new file mode 100644 index 0000000..6c3c54a Binary files /dev/null and b/Images/CA200.png differ diff --git a/Images/CA201.png b/Images/CA201.png new file mode 100644 index 0000000..686c40d Binary files /dev/null and b/Images/CA201.png differ diff --git a/Images/CA202.png b/Images/CA202.png new file mode 100644 index 0000000..b72b0a9 Binary files /dev/null and b/Images/CA202.png differ diff --git a/Images/CA203.png b/Images/CA203.png new file mode 100644 index 0000000..650f070 Binary files /dev/null and b/Images/CA203.png differ diff --git a/Images/CA204.png b/Images/CA204.png new file mode 100644 index 0000000..5316626 Binary files /dev/null and b/Images/CA204.png differ diff --git a/Images/CA205.png b/Images/CA205.png new file mode 100644 index 0000000..7d5a73c Binary files /dev/null and b/Images/CA205.png differ diff --git a/Images/CA400.png b/Images/CA400.png new file mode 100644 index 0000000..13b034f Binary files /dev/null and b/Images/CA400.png differ diff --git a/Images/CA401.png b/Images/CA401.png new file mode 100644 index 0000000..0a406b0 Binary files /dev/null and b/Images/CA401.png differ diff --git a/Images/CA402.png b/Images/CA402.png new file mode 100644 index 0000000..828298b Binary files /dev/null and b/Images/CA402.png differ diff --git a/README.md b/README.md index 121d1de..883ac5e 100644 --- a/README.md +++ b/README.md @@ -52,6 +52,8 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba ➡ Framework resources: https://github.com/microsoft/ConditionalAccessforZeroTrustResources +➡ idPowerToys for CA documentation: https://idpowertoys.merill.net/ + ## Version history @@ -101,6 +103,8 @@ that has been invited into the customer tenant This policy requires MFA for all cloud apps, from every platform. It captures all authentications in scope not captured by other MFA policies. +![CA000](./Images/CA000.png) + ### CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist This policy blocks all countries, to all cloud apps, from every platform except for the countries configured in the named location **ALLOWED COUNTRIES**. This named location is excluded in this policy. @@ -108,10 +112,15 @@ This policy blocks all countries, to all cloud apps, from every platform except > [!IMPORTANT] > Modify the named location with your approved countries. By default only Belgium, Luxembourgh and Netherlands are allowed to have access from. +![CA001](./Images/CA001.png) + + ### CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication This policy blocks legacy authentication for all users, to all cloud apps, from any platform. +![CA002](./Images/CA002.png) + ### CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA This policy requires MFA for all users, to register or join a device to your tenant/environment. @@ -119,55 +128,74 @@ This policy requires MFA for all users, to register or join a device to your ten > [!TIP] > Make sure to disable *Require Multifactor Authentication to register or join devices with Microsoft Entra*. This can be found under https://portal.azure.com -> Entra ID -> Devices -> Device settings. -![Image1](./Images/image1.png) +![CA003](./Images/CA003.png) ### CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows This policy prevents all users from transfering authentication flows from PC to mobile for example. This feature is currently in preview. +![CA004](./Images/CA004.png) + ### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload This policy prevents all users from downloading, printing or syncing Office 365 data from an unmanaged device. It requires App Enforce Restrictions. +![CA005](./Images/CA005.png) + ### CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA This policy requires MFA for certain admin roles when they access the Admin Portals. +![CA100](./Images/CA100.png) + ### CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA This policy requires MFA for certain admin roles when they access the any cloud app. +![CA101](./Images/CA101.png) + ### CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency This policy sets a Sign-in frequency for certain admin roles to a maximum of 12 hours. Admins need to re-authenticate of logon after 12 hours. +![CA102](./Images/CA102.png) + ### CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA This policy requires MFA for all internal identities, for all cloud applications, from any platform. + > [!IMPORTANT] -> Verify the included group(s) and/or add your custom groups which have all internals in it. +> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example. + +![CA200](./Images/CA200.png) ### CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk This policy blocks all internal users which have a **high risk** (sign-in and user risk) status, to all cloud apps, from all platforms. > [!IMPORTANT] -> Verify the included group(s) and/or add your custom groups which have all internals in it. +> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example. + +![CA201](./Images/CA201.png) ### CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices This policy sets a Sign-in frequency to a maximum of 12 hours for internals, to all cloud apps, using unmanaged Windows or MacOS devices. > [!IMPORTANT] -> Verify the included group(s) and/or add your custom groups which have all internals in it. +> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example. + +![CA202](./Images/CA202.png) ### CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA This policy requires MFA for internals when enrolling their devices in Intune. > [!IMPORTANT] -> Verify the included group(s) and/or add your custom groups which have all internals in it. +> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example. + +![CA203](./Images/CA203.png) ### CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms @@ -177,19 +205,25 @@ This policy blocks unknown/unsupported device platforms for internals. > Currently only Windows, MacOS, Android and iOS are supported. If (for example) Linux or Windows Phone is allowed you need to modify the policy. > [!IMPORTANT] -> Verify the included group(s) and/or add your custom groups which have all internals in it.. +> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example. + +![CA204](./Images/CA204.png) ### CA205-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ This policy requires internals to make use of a Windows device that is compliant or AADHJ (Azure AD Hybrid Joined / Entra ID Hybrid Joined) while accessing any cloud app. > [!IMPORTANT] -> Verify the included group(s) and/or add your custom groups which have all internals in it. +> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example. + +![CA205](./Images/CA205.png) ### CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA This policy requires guest to use MFA, from any platform when accessing any cloud app. +![CA400](./Images/CA400.png) + ### CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess This policy blocks access for guests to all cloud apps (except for those excluded), from any device @@ -197,10 +231,13 @@ This policy blocks access for guests to all cloud apps (except for those exclude > [!IMPORTANT] > Make sure to exclude additional cloud apps if any guest needs access to these apps. +![CA401](./Images/CA401.png) + ### CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency This policy sets a Sign-in frequency to a maximum of 12 hours for guests, to all cloud apps, using any device. +![CA402](./Images/CA402.png) ## Named locations