2026.2.1
This commit is contained in:
j0eyv
2026-02-13 14:35:36 +01:00
parent 927274b2cc
commit 8429d75b46
75 changed files with 36 additions and 241 deletions
@@ -1,126 +0,0 @@
{
"@odata.type": "#microsoft.graph.conditionalAccessPolicy",
"@odata.id": "identity/conditionalAccess/policies(\u00278cf1fcb1-c834-43c6-be35-5e11114999f8\u0027)",
"@odata.editLink": "identity/conditionalAccess/policies(\u00278cf1fcb1-c834-43c6-be35-5e11114999f8\u0027)",
"templateId": null,
"displayName": "CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload",
"createdDateTime@odata.type": "#DateTimeOffset",
"modifiedDateTime@odata.type": "#DateTimeOffset",
"state@odata.type": "#microsoft.graph.conditionalAccessPolicyState",
"state": "enabled",
"deletedDateTime": null,
"grantControls": null,
"partialEnablementStrategy": null,
"conditions": {
"@odata.type": "#microsoft.graph.conditionalAccessConditionSet",
"userRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
"userRiskLevels": [
],
"signInRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
"signInRiskLevels": [
],
"clientAppTypes@odata.type": "#Collection(microsoft.graph.conditionalAccessClientApp)",
"clientAppTypes": [
"browser"
],
"platforms": null,
"locations": null,
"times": null,
"deviceStates": null,
"clientApplications": null,
"applications": {
"@odata.type": "#microsoft.graph.conditionalAccessApplications",
"includeApplications@odata.type": "#Collection(String)",
"includeApplications": [
"Office365"
],
"excludeApplications@odata.type": "#Collection(String)",
"excludeApplications": [
],
"includeUserActions@odata.type": "#Collection(String)",
"includeUserActions": [
],
"includeAuthenticationContextClassReferences@odata.type": "#Collection(String)",
"includeAuthenticationContextClassReferences": [
],
"applicationFilter": null
},
"users": {
"@odata.type": "#microsoft.graph.conditionalAccessUsers",
"includeUsers@odata.type": "#Collection(String)",
"includeUsers": [
"All"
],
"excludeUsers@odata.type": "#Collection(String)",
"excludeUsers": [
],
"includeGroups@odata.type": "#Collection(String)",
"includeGroups": [
],
"excludeGroups@odata.type": "#Collection(String)",
"excludeGroups": [
"2802b872-ccfb-4b29-a9a9-459808dfb11b",
"20cd89e3-25e2-4fcd-82c5-de666dfd31a4"
],
"includeRoles@odata.type": "#Collection(String)",
"includeRoles": [
],
"excludeRoles@odata.type": "#Collection(String)",
"excludeRoles": [
],
"includeGuestsOrExternalUsers": null,
"excludeGuestsOrExternalUsers": null
},
"devices": {
"@odata.type": "#microsoft.graph.conditionalAccessDevices",
"includeDeviceStates@odata.type": "#Collection(String)",
"includeDeviceStates": [
],
"excludeDeviceStates@odata.type": "#Collection(String)",
"excludeDeviceStates": [
],
"includeDevices@odata.type": "#Collection(String)",
"includeDevices": [
],
"excludeDevices@odata.type": "#Collection(String)",
"excludeDevices": [
],
"deviceFilter": {
"@odata.type": "#microsoft.graph.conditionalAccessFilter",
"mode@odata.type": "#microsoft.graph.filterMode",
"mode": "exclude",
"rule": "device.isCompliant -eq True -and device.deviceOwnership -eq \"Company\""
}
}
},
"sessionControls": {
"@odata.type": "#microsoft.graph.conditionalAccessSessionControls",
"disableResilienceDefaults": null,
"cloudAppSecurity": null,
"signInFrequency": null,
"persistentBrowser": null,
"continuousAccessEvaluation": null,
"secureSignInSession": null,
"applicationEnforcedRestrictions": {
"@odata.type": "#microsoft.graph.applicationEnforcedRestrictionsSessionControl",
"isEnabled": true
}
},
"#microsoft.graph.restore": {
"title": "microsoft.graph.restore",
"target": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00278cf1fcb1-c834-43c6-be35-5e11114999f8\u0027)/microsoft.graph.restore"
}
}
@@ -1,108 +0,0 @@
{
"@odata.type": "#microsoft.graph.conditionalAccessPolicy",
"@odata.id": "identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)",
"@odata.editLink": "identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)",
"templateId": null,
"displayName": "CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn",
"createdDateTime@odata.type": "#DateTimeOffset",
"state@odata.type": "#microsoft.graph.conditionalAccessPolicyState",
"state": "enabled",
"deletedDateTime": null,
"partialEnablementStrategy": null,
"sessionControls": null,
"conditions": {
"@odata.type": "#microsoft.graph.conditionalAccessConditionSet",
"userRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
"userRiskLevels": [
],
"signInRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
"signInRiskLevels": [
"high"
],
"clientAppTypes@odata.type": "#Collection(microsoft.graph.conditionalAccessClientApp)",
"clientAppTypes": [
"all"
],
"platforms": null,
"locations": null,
"times": null,
"deviceStates": null,
"devices": null,
"clientApplications": null,
"applications": {
"@odata.type": "#microsoft.graph.conditionalAccessApplications",
"includeApplications@odata.type": "#Collection(String)",
"includeApplications": [
"All"
],
"excludeApplications@odata.type": "#Collection(String)",
"excludeApplications": [
],
"includeUserActions@odata.type": "#Collection(String)",
"includeUserActions": [
],
"includeAuthenticationContextClassReferences@odata.type": "#Collection(String)",
"includeAuthenticationContextClassReferences": [
],
"applicationFilter": null
},
"users": {
"@odata.type": "#microsoft.graph.conditionalAccessUsers",
"includeUsers@odata.type": "#Collection(String)",
"includeUsers": [
],
"excludeUsers@odata.type": "#Collection(String)",
"excludeUsers": [
],
"includeGroups@odata.type": "#Collection(String)",
"includeGroups": [
"ceeac9b8-ddf5-48cb-afcb-e2ab8bfd1a57"
],
"excludeGroups@odata.type": "#Collection(String)",
"excludeGroups": [
"2802b872-ccfb-4b29-a9a9-459808dfb11b",
"669c1f87-63ac-40c3-8fc2-fcc72e690e68"
],
"includeRoles@odata.type": "#Collection(String)",
"includeRoles": [
],
"excludeRoles@odata.type": "#Collection(String)",
"excludeRoles": [
],
"includeGuestsOrExternalUsers": null,
"excludeGuestsOrExternalUsers": null
}
},
"grantControls": {
"@odata.type": "#microsoft.graph.conditionalAccessGrantControls",
"operator": "OR",
"builtInControls@odata.type": "#Collection(microsoft.graph.conditionalAccessGrantControl)",
"builtInControls": [
"block"
],
"customAuthenticationFactors@odata.type": "#Collection(String)",
"customAuthenticationFactors": [
],
"termsOfUse@odata.type": "#Collection(String)",
"termsOfUse": [
],
"authenticationStrength@odata.context": "https://graph.microsoft.com/beta/$metadata#identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/grantControls/authenticationStrength/$entity",
"authenticationStrength@odata.associationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/grantControls/authenticationStrength/$ref",
"authenticationStrength@odata.navigationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/grantControls/authenticationStrength",
"authenticationStrength": null
},
"#microsoft.graph.restore": {
"title": "microsoft.graph.restore",
"target": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u0027a56ceb4f-0c7b-4379-a057-d5c6fabc4d94\u0027)/microsoft.graph.restore"
}
}
Binary file not shown.
Binary file not shown.
BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 185 KiB

After

Width:  |  Height:  |  Size: 169 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 175 KiB

After

Width:  |  Height:  |  Size: 170 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 139 KiB

After

Width:  |  Height:  |  Size: 156 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 203 KiB

After

Width:  |  Height:  |  Size: 230 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 131 KiB

After

Width:  |  Height:  |  Size: 150 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 238 KiB

After

Width:  |  Height:  |  Size: 216 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 191 KiB

After

Width:  |  Height:  |  Size: 182 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 191 KiB

After

Width:  |  Height:  |  Size: 181 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 197 KiB

After

Width:  |  Height:  |  Size: 177 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 158 KiB

After

Width:  |  Height:  |  Size: 180 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 123 KiB

After

Width:  |  Height:  |  Size: 172 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 139 KiB

After

Width:  |  Height:  |  Size: 175 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 142 KiB

After

Width:  |  Height:  |  Size: 182 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 140 KiB

After

Width:  |  Height:  |  Size: 166 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 206 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 138 KiB

After

Width:  |  Height:  |  Size: 155 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 156 KiB

After

Width:  |  Height:  |  Size: 175 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 138 KiB

After

Width:  |  Height:  |  Size: 157 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 150 KiB

After

Width:  |  Height:  |  Size: 168 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 150 KiB

After

Width:  |  Height:  |  Size: 164 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 186 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 162 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 166 KiB

After

Width:  |  Height:  |  Size: 163 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 165 KiB

After

Width:  |  Height:  |  Size: 161 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 125 KiB

After

Width:  |  Height:  |  Size: 156 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 206 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 198 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 159 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 138 KiB

After

Width:  |  Height:  |  Size: 157 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 148 KiB

After

Width:  |  Height:  |  Size: 167 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 139 KiB

After

Width:  |  Height:  |  Size: 158 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 162 KiB

After

Width:  |  Height:  |  Size: 159 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 175 KiB

After

Width:  |  Height:  |  Size: 170 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 134 KiB

+36 -7
View File
@@ -21,18 +21,20 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
- [2025.2.1](#202521)
- [2025.2.2](#202522)
- [2025.2.3](#202523)
- [2026.2.1](#202621)
- [Persona's](#personas)
- [Global](#global)
- [Admins](#admins)
- [Internals](#internals)
- [Guests](#guests)
- [Agents](#agents)
- [Conditional access policies](#conditional-access-policies)
- [CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca000-global-identityprotection-anyapp-anyplatform-mfa)
- [CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist](#ca001-global-attacksurfacereduction-anyapp-anyplatform-block-countrywhitelist)
- [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#ca002-global-identityprotection-anyapp-anyplatform-block-legacyauthentication)
- [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#ca003-global-baseprotection-registerorjoin-anyplatform-mfa)
- [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#ca004-global-identityprotection-anyapp-anyplatform-authenticationflows)
- [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload](#ca005-global-dataprotection-office365-anyplatform-unmanaged-appenforcedrestrictions-blockdownload)
- [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection](#ca005-global-dataprotection-office365-anyplatform-unmanaged-requireappprotection)
- [CA006-Global-DataProtection-Office365-iOSenAndroid-RequireAppProtection](#ca006-global-dataprotection-office365-iosenandroid-requireappprotection)
- [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#ca100-admins-identityprotection-adminportals-anyplatform-mfa)
- [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca101-admins-identityprotection-anyapp-anyplatform-mfa)
@@ -50,12 +52,14 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
- [CA207-Internals-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca207-internals-attacksurfacereduction-selectedapps-anyplatform-block)
- [CA208-Internals-BaseProtection-AnyApp-MacOS-Compliant](#ca208-internals-baseprotection-anyapp-macos-compliant)
- [CA209-Internals-IdentityProtection-AllApps-AnyPlatform-ContinuousAccessEvaluation](#ca209-internals-identityprotection-allapps-anyplatform-continuousaccessevaluation)
- [CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn](#ca210-internals-identityprotection-anyapp-anyplatform-block-highrisksignin)
- [CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca300-serviceaccounts-identityprotection-anyapp-anyplatform-mfa)
- [CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntrustedLocations](#ca301-serviceaccounts-attacksurfacereduction-allapps-anyplatform-blockuntrustedlocations)
- [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa)
- [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#ca401-guestusers-attacksurfacereduction-allapps-anyplatform-blocknonguestappaccess)
- [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca402-guestusers-identityprotection-allapps-anyplatform-signinfrequency)
- [CA403-Guests-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser](#ca403-guests-identityprotection-allapps-anyplatform-persistentbrowser)
- [CA404-Guests-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca404-guests-attacksurfacereduction-selectedapps-anyplatform-block)
- [CA501-Agents-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskAgent](#ca501-agents-identityprotection-anyapp-anyplatform-block-highriskagent)
- [Named locations](#named-locations)
- [Considerations](#considerations)
- [Troubleshooting](#troubleshooting)
@@ -90,6 +94,7 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
| 2025.2.1 | Released 01-02-2025 |
| 2025.2.2 | Released 06-02-2025 |
| 2025.2.3 | Released 13-02-2025 |
| 2026.2.1 | Released 13-02-2025 |
## Changelog
@@ -116,6 +121,11 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
* CA201: Policy contained Signin Risk and User Risk in a single policy. Now separated into CA201 and CA210
* CA210: Separated (new) policy for Signin Risk
### 2026.2.1
* CA501: Template policy for High Risk Agents adopted into the framework.
* CA005: Modified policy from **Require approved client app** to **RequireAppProtection** as this is being retired per March 2026.
## Persona's
#### Global
@@ -145,6 +155,9 @@ standard end-user role.
Guests holds all users who have an Azure AD guest account
that has been invited into the customer tenant
#### Agents
Agents covers all agent related resources which can be managed through Conditional Access
## Conditional access policies
@@ -184,9 +197,9 @@ This policy prevents all users from transfering authentication flows from PC to
![CA004](./Images/CA004.png)
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection
This policy prevents all users from downloading, printing or syncing Office 365 data from an unmanaged device. It requires App Enforce Restrictions.
This policyrequires App Protection Policies on unmanaged devices.
![CA005](./Images/CA005.png)
@@ -338,14 +351,23 @@ This policy allows Microsoft Entra ID to re-evaluate a user's access to resource
![CA209](./Images/CA209.png)
### CA210-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskSignIn
### CA300-ServiceAccounts-IdentityProtection-AnyApp-AnyPlatform-MFA
This policy blocks all internal users which have a **high risk** (Sign-in risk) status, to all cloud apps, from all platforms.
This policy requires ServiceAccounts to use MFA, from any platform when accessing any cloud app.
> [!IMPORTANT]
> Verify the included group(s) and/or add your custom groups which have all internals in it. APP_Microsoft365_E5 is added as an example.
![CA210](./Images/CA210.png)
![CA300](./Images/CA300.png)
### CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntrustedLocations
This policy prevents service accounts from logging in from untrusted countries.
> [!IMPORTANT]
> Verify the Named Location which is part of this policy. Add or Remove countries from the imported Named Location.
![CA301](./Images/CA301.png)
### CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
@@ -383,11 +405,18 @@ This policy prevents guests from accessing specific apps. In this example i've b
![CA404](./Images/CA404.png)
### CA501-Agents-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskAgent
This policy blocks agent identities with a high risk level from accessing resources in your tenant.
![CA501](./Images/CA501.png)
## Named locations
| Name | Location type | Assigned to policy |
| -------- | -------- | -------- |
| ALLOWED COUNTRIES | Countries (IP) | CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist |
| ALLOWED COUNTRIES - SERVICE ACCOUNTS | Countries (IP) | CA301-ServiceAccounts-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUntr|
## Considerations
1. You might want to remove the "CA - BreakGlassAccounts - Exclude" group from Admin MFA policies (CA101, CA102) if they use MFA and/or only exclude 1 single BreakGlass account.