2026.2.1
2026.2.1
@@ -1,126 +0,0 @@
|
|||||||
{
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessPolicy",
|
|
||||||
"@odata.id": "identity/conditionalAccess/policies(\u00278cf1fcb1-c834-43c6-be35-5e11114999f8\u0027)",
|
|
||||||
"@odata.editLink": "identity/conditionalAccess/policies(\u00278cf1fcb1-c834-43c6-be35-5e11114999f8\u0027)",
|
|
||||||
"templateId": null,
|
|
||||||
"displayName": "CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload",
|
|
||||||
"createdDateTime@odata.type": "#DateTimeOffset",
|
|
||||||
"modifiedDateTime@odata.type": "#DateTimeOffset",
|
|
||||||
"state@odata.type": "#microsoft.graph.conditionalAccessPolicyState",
|
|
||||||
"state": "enabled",
|
|
||||||
"deletedDateTime": null,
|
|
||||||
"grantControls": null,
|
|
||||||
"partialEnablementStrategy": null,
|
|
||||||
"conditions": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessConditionSet",
|
|
||||||
"userRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
|
|
||||||
"userRiskLevels": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"signInRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
|
|
||||||
"signInRiskLevels": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"clientAppTypes@odata.type": "#Collection(microsoft.graph.conditionalAccessClientApp)",
|
|
||||||
"clientAppTypes": [
|
|
||||||
"browser"
|
|
||||||
],
|
|
||||||
"platforms": null,
|
|
||||||
"locations": null,
|
|
||||||
"times": null,
|
|
||||||
"deviceStates": null,
|
|
||||||
"clientApplications": null,
|
|
||||||
"applications": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessApplications",
|
|
||||||
"includeApplications@odata.type": "#Collection(String)",
|
|
||||||
"includeApplications": [
|
|
||||||
"Office365"
|
|
||||||
],
|
|
||||||
"excludeApplications@odata.type": "#Collection(String)",
|
|
||||||
"excludeApplications": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeUserActions@odata.type": "#Collection(String)",
|
|
||||||
"includeUserActions": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeAuthenticationContextClassReferences@odata.type": "#Collection(String)",
|
|
||||||
"includeAuthenticationContextClassReferences": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"applicationFilter": null
|
|
||||||
},
|
|
||||||
"users": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessUsers",
|
|
||||||
"includeUsers@odata.type": "#Collection(String)",
|
|
||||||
"includeUsers": [
|
|
||||||
"All"
|
|
||||||
],
|
|
||||||
"excludeUsers@odata.type": "#Collection(String)",
|
|
||||||
"excludeUsers": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeGroups@odata.type": "#Collection(String)",
|
|
||||||
"includeGroups": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"excludeGroups@odata.type": "#Collection(String)",
|
|
||||||
"excludeGroups": [
|
|
||||||
"2802b872-ccfb-4b29-a9a9-459808dfb11b",
|
|
||||||
"20cd89e3-25e2-4fcd-82c5-de666dfd31a4"
|
|
||||||
],
|
|
||||||
"includeRoles@odata.type": "#Collection(String)",
|
|
||||||
"includeRoles": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"excludeRoles@odata.type": "#Collection(String)",
|
|
||||||
"excludeRoles": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeGuestsOrExternalUsers": null,
|
|
||||||
"excludeGuestsOrExternalUsers": null
|
|
||||||
},
|
|
||||||
"devices": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessDevices",
|
|
||||||
"includeDeviceStates@odata.type": "#Collection(String)",
|
|
||||||
"includeDeviceStates": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"excludeDeviceStates@odata.type": "#Collection(String)",
|
|
||||||
"excludeDeviceStates": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeDevices@odata.type": "#Collection(String)",
|
|
||||||
"includeDevices": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"excludeDevices@odata.type": "#Collection(String)",
|
|
||||||
"excludeDevices": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"deviceFilter": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessFilter",
|
|
||||||
"mode@odata.type": "#microsoft.graph.filterMode",
|
|
||||||
"mode": "exclude",
|
|
||||||
"rule": "device.isCompliant -eq True -and device.deviceOwnership -eq \"Company\""
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"sessionControls": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessSessionControls",
|
|
||||||
"disableResilienceDefaults": null,
|
|
||||||
"cloudAppSecurity": null,
|
|
||||||
"signInFrequency": null,
|
|
||||||
"persistentBrowser": null,
|
|
||||||
"continuousAccessEvaluation": null,
|
|
||||||
"secureSignInSession": null,
|
|
||||||
"applicationEnforcedRestrictions": {
|
|
||||||
"@odata.type": "#microsoft.graph.applicationEnforcedRestrictionsSessionControl",
|
|
||||||
"isEnabled": true
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"#microsoft.graph.restore": {
|
|
||||||
"title": "microsoft.graph.restore",
|
|
||||||
"target": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00278cf1fcb1-c834-43c6-be35-5e11114999f8\u0027)/microsoft.graph.restore"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,108 +0,0 @@
|
|||||||
{
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessPolicy",
|
|
||||||
"@odata.id": "identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)",
|
|
||||||
"@odata.editLink": "identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)",
|
|
||||||
"templateId": null,
|
|
||||||
"displayName": "CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn",
|
|
||||||
"createdDateTime@odata.type": "#DateTimeOffset",
|
|
||||||
"state@odata.type": "#microsoft.graph.conditionalAccessPolicyState",
|
|
||||||
"state": "enabled",
|
|
||||||
"deletedDateTime": null,
|
|
||||||
"partialEnablementStrategy": null,
|
|
||||||
"sessionControls": null,
|
|
||||||
"conditions": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessConditionSet",
|
|
||||||
"userRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
|
|
||||||
"userRiskLevels": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"signInRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
|
|
||||||
"signInRiskLevels": [
|
|
||||||
"high"
|
|
||||||
],
|
|
||||||
"clientAppTypes@odata.type": "#Collection(microsoft.graph.conditionalAccessClientApp)",
|
|
||||||
"clientAppTypes": [
|
|
||||||
"all"
|
|
||||||
],
|
|
||||||
"platforms": null,
|
|
||||||
"locations": null,
|
|
||||||
"times": null,
|
|
||||||
"deviceStates": null,
|
|
||||||
"devices": null,
|
|
||||||
"clientApplications": null,
|
|
||||||
"applications": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessApplications",
|
|
||||||
"includeApplications@odata.type": "#Collection(String)",
|
|
||||||
"includeApplications": [
|
|
||||||
"All"
|
|
||||||
],
|
|
||||||
"excludeApplications@odata.type": "#Collection(String)",
|
|
||||||
"excludeApplications": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeUserActions@odata.type": "#Collection(String)",
|
|
||||||
"includeUserActions": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeAuthenticationContextClassReferences@odata.type": "#Collection(String)",
|
|
||||||
"includeAuthenticationContextClassReferences": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"applicationFilter": null
|
|
||||||
},
|
|
||||||
"users": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessUsers",
|
|
||||||
"includeUsers@odata.type": "#Collection(String)",
|
|
||||||
"includeUsers": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"excludeUsers@odata.type": "#Collection(String)",
|
|
||||||
"excludeUsers": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeGroups@odata.type": "#Collection(String)",
|
|
||||||
"includeGroups": [
|
|
||||||
"ceeac9b8-ddf5-48cb-afcb-e2ab8bfd1a57"
|
|
||||||
],
|
|
||||||
"excludeGroups@odata.type": "#Collection(String)",
|
|
||||||
"excludeGroups": [
|
|
||||||
"2802b872-ccfb-4b29-a9a9-459808dfb11b",
|
|
||||||
"669c1f87-63ac-40c3-8fc2-fcc72e690e68"
|
|
||||||
],
|
|
||||||
"includeRoles@odata.type": "#Collection(String)",
|
|
||||||
"includeRoles": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"excludeRoles@odata.type": "#Collection(String)",
|
|
||||||
"excludeRoles": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"includeGuestsOrExternalUsers": null,
|
|
||||||
"excludeGuestsOrExternalUsers": null
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"grantControls": {
|
|
||||||
"@odata.type": "#microsoft.graph.conditionalAccessGrantControls",
|
|
||||||
"operator": "OR",
|
|
||||||
"builtInControls@odata.type": "#Collection(microsoft.graph.conditionalAccessGrantControl)",
|
|
||||||
"builtInControls": [
|
|
||||||
"block"
|
|
||||||
],
|
|
||||||
"customAuthenticationFactors@odata.type": "#Collection(String)",
|
|
||||||
"customAuthenticationFactors": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"termsOfUse@odata.type": "#Collection(String)",
|
|
||||||
"termsOfUse": [
|
|
||||||
|
|
||||||
],
|
|
||||||
"authenticationStrength@odata.context": "https://graph.microsoft.com/beta/$metadata#identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/grantControls/authenticationStrength/$entity",
|
|
||||||
"authenticationStrength@odata.associationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/grantControls/authenticationStrength/$ref",
|
|
||||||
"authenticationStrength@odata.navigationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/grantControls/authenticationStrength",
|
|
||||||
"authenticationStrength": null
|
|
||||||
},
|
|
||||||
"#microsoft.graph.restore": {
|
|
||||||
"title": "microsoft.graph.restore",
|
|
||||||
"target": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/microsoft.graph.restore"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
Before Width: | Height: | Size: 185 KiB After Width: | Height: | Size: 169 KiB |
|
Before Width: | Height: | Size: 175 KiB After Width: | Height: | Size: 170 KiB |
|
Before Width: | Height: | Size: 139 KiB After Width: | Height: | Size: 156 KiB |
|
Before Width: | Height: | Size: 203 KiB After Width: | Height: | Size: 230 KiB |
|
Before Width: | Height: | Size: 131 KiB After Width: | Height: | Size: 150 KiB |
|
Before Width: | Height: | Size: 238 KiB After Width: | Height: | Size: 216 KiB |
|
Before Width: | Height: | Size: 191 KiB After Width: | Height: | Size: 182 KiB |
|
Before Width: | Height: | Size: 191 KiB After Width: | Height: | Size: 181 KiB |
|
Before Width: | Height: | Size: 197 KiB After Width: | Height: | Size: 177 KiB |
|
Before Width: | Height: | Size: 158 KiB After Width: | Height: | Size: 180 KiB |
|
Before Width: | Height: | Size: 123 KiB After Width: | Height: | Size: 172 KiB |
|
Before Width: | Height: | Size: 139 KiB After Width: | Height: | Size: 175 KiB |
|
Before Width: | Height: | Size: 142 KiB After Width: | Height: | Size: 182 KiB |
|
Before Width: | Height: | Size: 140 KiB After Width: | Height: | Size: 166 KiB |
|
Before Width: | Height: | Size: 206 KiB |
|
Before Width: | Height: | Size: 138 KiB After Width: | Height: | Size: 155 KiB |
|
Before Width: | Height: | Size: 156 KiB After Width: | Height: | Size: 175 KiB |
|
Before Width: | Height: | Size: 138 KiB After Width: | Height: | Size: 157 KiB |
|
Before Width: | Height: | Size: 150 KiB After Width: | Height: | Size: 168 KiB |
|
Before Width: | Height: | Size: 150 KiB After Width: | Height: | Size: 164 KiB |
|
Before Width: | Height: | Size: 186 KiB |
|
After Width: | Height: | Size: 162 KiB |
|
Before Width: | Height: | Size: 166 KiB After Width: | Height: | Size: 163 KiB |
|
Before Width: | Height: | Size: 165 KiB After Width: | Height: | Size: 161 KiB |
|
Before Width: | Height: | Size: 125 KiB After Width: | Height: | Size: 156 KiB |
|
Before Width: | Height: | Size: 206 KiB |
|
After Width: | Height: | Size: 198 KiB |
|
After Width: | Height: | Size: 159 KiB |
|
Before Width: | Height: | Size: 138 KiB After Width: | Height: | Size: 157 KiB |
|
Before Width: | Height: | Size: 148 KiB After Width: | Height: | Size: 167 KiB |
|
Before Width: | Height: | Size: 139 KiB After Width: | Height: | Size: 158 KiB |
|
Before Width: | Height: | Size: 162 KiB After Width: | Height: | Size: 159 KiB |
|
Before Width: | Height: | Size: 175 KiB After Width: | Height: | Size: 170 KiB |
|
After Width: | Height: | Size: 134 KiB |
@@ -21,18 +21,20 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
- [2025.2.1](#202521)
|
- [2025.2.1](#202521)
|
||||||
- [2025.2.2](#202522)
|
- [2025.2.2](#202522)
|
||||||
- [2025.2.3](#202523)
|
- [2025.2.3](#202523)
|
||||||
|
- [2026.2.1](#202621)
|
||||||
- [Persona's](#personas)
|
- [Persona's](#personas)
|
||||||
- [Global](#global)
|
- [Global](#global)
|
||||||
- [Admins](#admins)
|
- [Admins](#admins)
|
||||||
- [Internals](#internals)
|
- [Internals](#internals)
|
||||||
- [Guests](#guests)
|
- [Guests](#guests)
|
||||||
|
- [Agents](#agents)
|
||||||
- [Conditional access policies](#conditional-access-policies)
|
- [Conditional access policies](#conditional-access-policies)
|
||||||
- [CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca000-global-identityprotection-anyapp-anyplatform-mfa)
|
- [CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca000-global-identityprotection-anyapp-anyplatform-mfa)
|
||||||
- [CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist](#ca001-global-attacksurfacereduction-anyapp-anyplatform-block-countrywhitelist)
|
- [CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist](#ca001-global-attacksurfacereduction-anyapp-anyplatform-block-countrywhitelist)
|
||||||
- [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#ca002-global-identityprotection-anyapp-anyplatform-block-legacyauthentication)
|
- [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#ca002-global-identityprotection-anyapp-anyplatform-block-legacyauthentication)
|
||||||
- [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#ca003-global-baseprotection-registerorjoin-anyplatform-mfa)
|
- [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#ca003-global-baseprotection-registerorjoin-anyplatform-mfa)
|
||||||
- [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#ca004-global-identityprotection-anyapp-anyplatform-authenticationflows)
|
- [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#ca004-global-identityprotection-anyapp-anyplatform-authenticationflows)
|
||||||
- [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload](#ca005-global-dataprotection-office365-anyplatform-unmanaged-appenforcedrestrictions-blockdownload)
|
- [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection](#ca005-global-dataprotection-office365-anyplatform-unmanaged-requireappprotection)
|
||||||
- [CA006-Global-DataProtection-Office365-iOSenAndroid-RequireAppProtection](#ca006-global-dataprotection-office365-iosenandroid-requireappprotection)
|
- [CA006-Global-DataProtection-Office365-iOSenAndroid-RequireAppProtection](#ca006-global-dataprotection-office365-iosenandroid-requireappprotection)
|
||||||
- [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#ca100-admins-identityprotection-adminportals-anyplatform-mfa)
|
- [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#ca100-admins-identityprotection-adminportals-anyplatform-mfa)
|
||||||
- [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca101-admins-identityprotection-anyapp-anyplatform-mfa)
|
- [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca101-admins-identityprotection-anyapp-anyplatform-mfa)
|
||||||
@@ -50,12 +52,14 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
- [CA207-Internals-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca207-internals-attacksurfacereduction-selectedapps-anyplatform-block)
|
- [CA207-Internals-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca207-internals-attacksurfacereduction-selectedapps-anyplatform-block)
|
||||||
- [CA208-Internals-BaseProtection-AnyApp-MacOS-Compliant](#ca208-internals-baseprotection-anyapp-macos-compliant)
|
- [CA208-Internals-BaseProtection-AnyApp-MacOS-Compliant](#ca208-internals-baseprotection-anyapp-macos-compliant)
|
||||||
- [CA209-Internals-IdentityProtection-AllApps-AnyPlatform-ContinuousAccessEvaluation](#ca209-internals-identityprotection-allapps-anyplatform-continuousaccessevaluation)
|
- [CA209-Internals-IdentityProtection-AllApps-AnyPlatform-ContinuousAccessEvaluation](#ca209-internals-identityprotection-allapps-anyplatform-continuousaccessevaluation)
|
||||||
- [CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn](#ca210-internals-identityprotection-anyapp-anyplatform-block-highrisksignin)
|
- [CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca300-serviceaccounts-identityprotection-anyapp-anyplatform-mfa)
|
||||||
|
- [CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntrustedLocations](#ca301-serviceaccounts-attacksurfacereduction-allapps-anyplatform-blockuntrustedlocations)
|
||||||
- [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa)
|
- [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa)
|
||||||
- [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#ca401-guestusers-attacksurfacereduction-allapps-anyplatform-blocknonguestappaccess)
|
- [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#ca401-guestusers-attacksurfacereduction-allapps-anyplatform-blocknonguestappaccess)
|
||||||
- [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca402-guestusers-identityprotection-allapps-anyplatform-signinfrequency)
|
- [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca402-guestusers-identityprotection-allapps-anyplatform-signinfrequency)
|
||||||
- [CA403-Guests-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser](#ca403-guests-identityprotection-allapps-anyplatform-persistentbrowser)
|
- [CA403-Guests-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser](#ca403-guests-identityprotection-allapps-anyplatform-persistentbrowser)
|
||||||
- [CA404-Guests-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca404-guests-attacksurfacereduction-selectedapps-anyplatform-block)
|
- [CA404-Guests-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca404-guests-attacksurfacereduction-selectedapps-anyplatform-block)
|
||||||
|
- [CA501-Agents-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskAgent](#ca501-agents-identityprotection-anyapp-anyplatform-block-highriskagent)
|
||||||
- [Named locations](#named-locations)
|
- [Named locations](#named-locations)
|
||||||
- [Considerations](#considerations)
|
- [Considerations](#considerations)
|
||||||
- [Troubleshooting](#troubleshooting)
|
- [Troubleshooting](#troubleshooting)
|
||||||
@@ -90,6 +94,7 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
| 2025.2.1 | Released 01-02-2025 |
|
| 2025.2.1 | Released 01-02-2025 |
|
||||||
| 2025.2.2 | Released 06-02-2025 |
|
| 2025.2.2 | Released 06-02-2025 |
|
||||||
| 2025.2.3 | Released 13-02-2025 |
|
| 2025.2.3 | Released 13-02-2025 |
|
||||||
|
| 2026.2.1 | Released 13-02-2025 |
|
||||||
|
|
||||||
|
|
||||||
## Changelog
|
## Changelog
|
||||||
@@ -116,6 +121,11 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
* CA201: Policy contained Signin Risk and User Risk in a single policy. Now separated into CA201 and CA210
|
* CA201: Policy contained Signin Risk and User Risk in a single policy. Now separated into CA201 and CA210
|
||||||
* CA210: Separated (new) policy for Signin Risk
|
* CA210: Separated (new) policy for Signin Risk
|
||||||
|
|
||||||
|
### 2026.2.1
|
||||||
|
* CA501: Template policy for High Risk Agents adopted into the framework.
|
||||||
|
* CA005: Modified policy from **Require approved client app** to **RequireAppProtection** as this is being retired per March 2026.
|
||||||
|
|
||||||
|
|
||||||
## Persona's
|
## Persona's
|
||||||
|
|
||||||
#### Global
|
#### Global
|
||||||
@@ -145,6 +155,9 @@ standard end-user role.
|
|||||||
Guests holds all users who have an Azure AD guest account
|
Guests holds all users who have an Azure AD guest account
|
||||||
that has been invited into the customer tenant
|
that has been invited into the customer tenant
|
||||||
|
|
||||||
|
#### Agents
|
||||||
|
Agents covers all agent related resources which can be managed through Conditional Access
|
||||||
|
|
||||||
|
|
||||||
## Conditional access policies
|
## Conditional access policies
|
||||||
|
|
||||||
@@ -184,9 +197,9 @@ This policy prevents all users from transfering authentication flows from PC to
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
|
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection
|
||||||
|
|
||||||
This policy prevents all users from downloading, printing or syncing Office 365 data from an unmanaged device. It requires App Enforce Restrictions.
|
This policyrequires App Protection Policies on unmanaged devices.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@@ -338,14 +351,23 @@ This policy allows Microsoft Entra ID to re-evaluate a user's access to resource
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
### CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn
|
### CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA
|
||||||
|
|
||||||
This policy blocks all internal users which have a **high risk** (Sign-in risk) status, to all cloud apps, from all platforms.
|
This policy requires ServiceAccounts to use MFA, from any platform when accessing any cloud app.
|
||||||
|
|
||||||
> [!IMPORTANT]
|
> [!IMPORTANT]
|
||||||
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example.
|
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
### CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntrustedLocations
|
||||||
|
|
||||||
|
This policy prevents service accounts from logging in from untrusted countries.
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> Verify the Named Location which is part of this policy. Add or Remove countries from the imported Named Location.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
### CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
|
### CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
|
||||||
|
|
||||||
@@ -383,11 +405,18 @@ This policy prevents guests from accessing specific apps. In this example i've b
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
### CA501-Agents-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskAgent
|
||||||
|
|
||||||
|
This policy blocks agent identities with a high risk level from accessing resources in your tenant.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
## Named locations
|
## Named locations
|
||||||
|
|
||||||
| Name | Location type | Assigned to policy |
|
| Name | Location type | Assigned to policy |
|
||||||
| -------- | -------- | -------- |
|
| -------- | -------- | -------- |
|
||||||
| ALLOWED COUNTRIES | Countries (IP) | CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist |
|
| ALLOWED COUNTRIES | Countries (IP) | CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist |
|
||||||
|
| ALLOWED COUNTRIES - SERVICE ACCOUNTS | Countries (IP) | CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntr|
|
||||||
|
|
||||||
## Considerations
|
## Considerations
|
||||||
1. You might want to remove the "CA - BreakGlassAccounts - Exclude" group from Admin MFA policies (CA101, CA102) if they use MFA and/or only exclude 1 single BreakGlass account.
|
1. You might want to remove the "CA - BreakGlassAccounts - Exclude" group from Admin MFA policies (CA101, CA102) if they use MFA and/or only exclude 1 single BreakGlass account.
|
||||||
|
|||||||