Updated readme. Added images.
Updated readme. Added images.
|
After Width: | Height: | Size: 185 KiB |
|
After Width: | Height: | Size: 175 KiB |
|
After Width: | Height: | Size: 139 KiB |
|
After Width: | Height: | Size: 203 KiB |
|
After Width: | Height: | Size: 131 KiB |
|
After Width: | Height: | Size: 154 KiB |
|
After Width: | Height: | Size: 167 KiB |
|
After Width: | Height: | Size: 169 KiB |
|
After Width: | Height: | Size: 158 KiB |
|
After Width: | Height: | Size: 140 KiB |
|
After Width: | Height: | Size: 138 KiB |
|
After Width: | Height: | Size: 156 KiB |
|
After Width: | Height: | Size: 138 KiB |
|
After Width: | Height: | Size: 150 KiB |
|
After Width: | Height: | Size: 150 KiB |
|
After Width: | Height: | Size: 138 KiB |
|
After Width: | Height: | Size: 148 KiB |
|
After Width: | Height: | Size: 139 KiB |
@@ -52,6 +52,8 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
|
|
||||||
➡ Framework resources: https://github.com/microsoft/ConditionalAccessforZeroTrustResources
|
➡ Framework resources: https://github.com/microsoft/ConditionalAccessforZeroTrustResources
|
||||||
|
|
||||||
|
➡ idPowerToys for CA documentation: https://idpowertoys.merill.net/
|
||||||
|
|
||||||
|
|
||||||
## Version history
|
## Version history
|
||||||
|
|
||||||
@@ -101,6 +103,8 @@ that has been invited into the customer tenant
|
|||||||
|
|
||||||
This policy requires MFA for all cloud apps, from every platform. It captures all authentications in scope not captured by other MFA policies.
|
This policy requires MFA for all cloud apps, from every platform. It captures all authentications in scope not captured by other MFA policies.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
|
### CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
|
||||||
|
|
||||||
This policy blocks all countries, to all cloud apps, from every platform except for the countries configured in the named location **ALLOWED COUNTRIES**. This named location is excluded in this policy.
|
This policy blocks all countries, to all cloud apps, from every platform except for the countries configured in the named location **ALLOWED COUNTRIES**. This named location is excluded in this policy.
|
||||||
@@ -108,10 +112,15 @@ This policy blocks all countries, to all cloud apps, from every platform except
|
|||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Modify the named location with your approved countries. By default only Belgium, Luxembourgh and Netherlands are allowed to have access from.
|
> Modify the named location with your approved countries. By default only Belgium, Luxembourgh and Netherlands are allowed to have access from.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
|
||||||
### CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
|
### CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
|
||||||
|
|
||||||
This policy blocks legacy authentication for all users, to all cloud apps, from any platform.
|
This policy blocks legacy authentication for all users, to all cloud apps, from any platform.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
|
### CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
|
||||||
|
|
||||||
This policy requires MFA for all users, to register or join a device to your tenant/environment.
|
This policy requires MFA for all users, to register or join a device to your tenant/environment.
|
||||||
@@ -119,55 +128,74 @@ This policy requires MFA for all users, to register or join a device to your ten
|
|||||||
> [!TIP]
|
> [!TIP]
|
||||||
> Make sure to disable *Require Multifactor Authentication to register or join devices with Microsoft Entra*. This can be found under https://portal.azure.com -> Entra ID -> Devices -> Device settings.
|
> Make sure to disable *Require Multifactor Authentication to register or join devices with Microsoft Entra*. This can be found under https://portal.azure.com -> Entra ID -> Devices -> Device settings.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
### CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
|
### CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
|
||||||
|
|
||||||
This policy prevents all users from transfering authentication flows from PC to mobile for example. This feature is currently in preview.
|
This policy prevents all users from transfering authentication flows from PC to mobile for example. This feature is currently in preview.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
|
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
|
||||||
|
|
||||||
This policy prevents all users from downloading, printing or syncing Office 365 data from an unmanaged device. It requires App Enforce Restrictions.
|
This policy prevents all users from downloading, printing or syncing Office 365 data from an unmanaged device. It requires App Enforce Restrictions.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
|
### CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
|
||||||
|
|
||||||
This policy requires MFA for certain admin roles when they access the Admin Portals.
|
This policy requires MFA for certain admin roles when they access the Admin Portals.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
|
### CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
|
||||||
|
|
||||||
This policy requires MFA for certain admin roles when they access the any cloud app.
|
This policy requires MFA for certain admin roles when they access the any cloud app.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
|
### CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
|
||||||
|
|
||||||
This policy sets a Sign-in frequency for certain admin roles to a maximum of 12 hours. Admins need to re-authenticate of logon after 12 hours.
|
This policy sets a Sign-in frequency for certain admin roles to a maximum of 12 hours. Admins need to re-authenticate of logon after 12 hours.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
|
### CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
|
||||||
|
|
||||||
This policy requires MFA for all internal identities, for all cloud applications, from any platform.
|
This policy requires MFA for all internal identities, for all cloud applications, from any platform.
|
||||||
|
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Verify the included group(s) and/or add your custom groups which have all internals in it.
|
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
|
### CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
|
||||||
|
|
||||||
This policy blocks all internal users which have a **high risk** (sign-in and user risk) status, to all cloud apps, from all platforms.
|
This policy blocks all internal users which have a **high risk** (sign-in and user risk) status, to all cloud apps, from all platforms.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Verify the included group(s) and/or add your custom groups which have all internals in it.
|
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
|
### CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
|
||||||
|
|
||||||
This policy sets a Sign-in frequency to a maximum of 12 hours for internals, to all cloud apps, using unmanaged Windows or MacOS devices.
|
This policy sets a Sign-in frequency to a maximum of 12 hours for internals, to all cloud apps, using unmanaged Windows or MacOS devices.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Verify the included group(s) and/or add your custom groups which have all internals in it.
|
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
|
### CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
|
||||||
|
|
||||||
This policy requires MFA for internals when enrolling their devices in Intune.
|
This policy requires MFA for internals when enrolling their devices in Intune.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Verify the included group(s) and/or add your custom groups which have all internals in it.
|
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
|
### CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
|
||||||
|
|
||||||
@@ -177,19 +205,25 @@ This policy blocks unknown/unsupported device platforms for internals.
|
|||||||
> Currently only Windows, MacOS, Android and iOS are supported. If (for example) Linux or Windows Phone is allowed you need to modify the policy.
|
> Currently only Windows, MacOS, Android and iOS are supported. If (for example) Linux or Windows Phone is allowed you need to modify the policy.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Verify the included group(s) and/or add your custom groups which have all internals in it..
|
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA205-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
|
### CA205-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
|
||||||
|
|
||||||
This policy requires internals to make use of a Windows device that is compliant or AADHJ (Azure AD Hybrid Joined / Entra ID Hybrid Joined) while accessing any cloud app.
|
This policy requires internals to make use of a Windows device that is compliant or AADHJ (Azure AD Hybrid Joined / Entra ID Hybrid Joined) while accessing any cloud app.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Verify the included group(s) and/or add your custom groups which have all internals in it.
|
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5_DEV is added as an example.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
|
### CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
|
||||||
|
|
||||||
This policy requires guest to use MFA, from any platform when accessing any cloud app.
|
This policy requires guest to use MFA, from any platform when accessing any cloud app.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
|
### CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
|
||||||
|
|
||||||
This policy blocks access for guests to all cloud apps (except for those excluded), from any device
|
This policy blocks access for guests to all cloud apps (except for those excluded), from any device
|
||||||
@@ -197,10 +231,13 @@ This policy blocks access for guests to all cloud apps (except for those exclude
|
|||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Make sure to exclude additional cloud apps if any guest needs access to these apps.
|
> Make sure to exclude additional cloud apps if any guest needs access to these apps.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
|
### CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
|
||||||
|
|
||||||
This policy sets a Sign-in frequency to a maximum of 12 hours for guests, to all cloud apps, using any device.
|
This policy sets a Sign-in frequency to a maximum of 12 hours for guests, to all cloud apps, using any device.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
## Named locations
|
## Named locations
|
||||||
|
|
||||||
|
|||||||