diff --git a/README.md b/README.md index dc2c1a0..18898b9 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,38 @@ -# Conditional Access Baseline +# Conditional access Baselne + +This conditional access baseline is based on the Microsoft Conditional Access Baseline by Claus Jespersen. This one is slightly minimized and less dificult to understand but still protects almost everything you could wish for. Use this baseline to start off with and expend or modify where needed. + + +# Table of Contents +- [Conditional access Baselne](#conditional-access-baselne) +- [Table of Contents](#table-of-contents) + - [Resources](#resources) + - [Version history](#version-history) + - [Changelog](#changelog) + - [Conditional access policies](#conditional-access-policies) + - [CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca000-global-identityprotection-anyapp-anyplatform-mfa) + - [CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca000-global-identityprotection-anyapp-anyplatform-mfa-1) + - [CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist](#ca001-global-attacksurfacereduction-anyapp-anyplatform-block-countrywhitelist) + - [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#ca002-global-identityprotection-anyapp-anyplatform-block-legacyauthentication) + - [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#ca003-global-baseprotection-registerorjoin-anyplatform-mfa) + - [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#ca004-global-identityprotection-anyapp-anyplatform-authenticationflows) + - [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload](#ca005-global-dataprotection-office365-anyplatform-unmanaged-appenforcedrestrictions-blockdownload) + - [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#ca100-admins-identityprotection-adminportals-anyplatform-mfa) + - [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca101-admins-identityprotection-anyapp-anyplatform-mfa) + - [CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca102-admins-identityprotection-allapps-anyplatform-signinfrequency) + - [CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca200-internals-identityprotection-anyapp-anyplatform-mfa) + - [CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk](#ca201-internals-identityprotection-anyapp-anyplatform-block-highrisk) + - [CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices](#ca202-internals-identityprotection-allapps-windowsmacos-signinfrequency-unmanageddevices) + - [CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA](#ca203-internals-appprotection-microsoftintuneenrollment-anyplatform-mfa) + - [CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms](#ca204-internals-attacksurfacereduction-allapps-anyplatform-blockunknownplatforms) + - [CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration](#ca205-internals-identityprotection-allapps-anyplatform-combinedregistration) + - [CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ](#ca206-internals-baseprotection-anyapp-windows-compliantoraadhj) + - [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa) + - [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#ca401-guestusers-attacksurfacereduction-allapps-anyplatform-blocknonguestappaccess) + - [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca402-guestusers-identityprotection-allapps-anyplatform-signinfrequency) + - [Named locations](#named-locations) + - [Importing the baseline](#importing-the-baseline) -This conditional access baseline is based on the Microsoft Conditional Access Baseline by Claus Jespersen. This one is slightly minimized and less dificult to understand but still protects almost everything you could wish for. Use this baseline to start off with and expend where needed. ## Resources ➡ Microsoft Learn: https://learn.microsoft.com/en-us/azure/architecture/guide/security/conditional-access-framework @@ -10,1804 +42,45 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba ➡ Framework resources: https://github.com/microsoft/ConditionalAccessforZeroTrustResources +## Version history -## Table of Contents -- [Conditional Access Baseline](#conditional-access-baseline) - - [Resources](#resources) - - [Table of Contents](#table-of-contents) - - [Table 3. Basics - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist](#table-3-basics---ca001-global-attacksurfacereduction-anyapp-anyplatform-block-countrywhitelist) - - [Table 14. Settings - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#table-14-settings---ca100-admins-identityprotection-adminportals-anyplatform-mfa) +| Version nr | Release date | +| -------- | -------- | +| 2024.4.1 | Released 10-04-2024 | +| 2024.x.x | Released xx-xx-2024 | -

Conditional access

-

Conditional access policies

-

CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA

+## Changelog - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:47:07
Last modifiedWednesday, 27 March 2024 14:41:39
+Changes are documented here once they are made. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeAll users
Exclude
Directory rolesDirectory Synchronization Accounts
Users and groups
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
+## Conditional access policies -

CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist

+### CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA +### CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA +### CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist +### CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication +### CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA +### CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows +### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload +### CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA +### CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA +### CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency +### CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA +### CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk +### CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices +### CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA +### CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms +### CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration +### CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ +### CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA +### CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess +### CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 08:02:06
Last modifiedTuesday, 2 January 2024 10:38:04
-###### Table 3. Basics - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Locations
IncludeAny location
ExcludeALLOWED COUNTRIES
Grant
Control access enforcement to block or grant access.Block access
- -

CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:08:14
Last modifiedTuesday, 2 January 2024 10:38:10
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Client apps
IncludeExchange ActiveSync
Other clients
Grant
Control access enforcement to block or grant access.Block access
- - -

CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA

- - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 3 January 2024 07:52:15
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA - Exclude
Cloud apps or actions
User actions
Select the action this policy will apply toRegister or join devices
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
- - -

CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 27 March 2024 14:28:00
Last modifiedMonday, 8 April 2024 12:38:51
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Block access
- - -

CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 27 March 2024 14:40:41
Last modifiedMonday, 8 April 2024 12:38:39
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeAll users
Exclude
Users and groupsCA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeOffice 365 Exchange Online
Office 365 SharePoint Online
Conditions
Client apps
IncludeBrowser
Filter for devices
Exclude filtered devices from policydevice.isCompliant -eq True
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Use app enforced restrictionsEnabled
- - -

CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedFriday, 22 December 2023 10:12:23
Last modifiedWednesday, 3 January 2024 09:43:35
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Directory roles
Global Administrator
Security Administrator
SharePoint Administrator
Exchange Administrator
Conditional Access Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Application Administrator
Cloud Application Administrator
Password Administrator
Privileged Authentication Administrator
Privileged Role Administrator
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeMicrosoftAdminPortals
Grant
Control access enforcement to block or grant access.Grant access
Authentication strength
For multiple controlsRequire one of the selected controls
- -###### Table 14. Settings - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA - - -

CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedMonday, 31 January 2022 16:44:43
Last modifiedTuesday, 2 January 2024 10:38:19
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Directory roles
Exchange Administrator
Security Administrator
Conditional Access Administrator
SharePoint Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Global Administrator
Global Reader
Intune Administrator
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Locations
IncludeAny location
Client apps
IncludeExchange ActiveSync
Browser
Mobile apps and desktop clients
Other clients
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
- - -

CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 10:02:19
Last modifiedTuesday, 2 January 2024 10:38:23
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Directory roles
Authentication Administrator
Billing Administrator
Conditional Access Administrator
Exchange Administrator
Global Administrator
Global Reader
Helpdesk Administrator
Intune Administrator
Security Administrator
User Administrator
SharePoint Administrator
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Sign-in frequency12 hours
- - - -

CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedMonday, 31 January 2022 16:44:44
Last modifiedTuesday, 2 January 2024 14:10:23
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Locations
IncludeAny location
Client apps
IncludeBrowser
Mobile apps and desktop clients
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
- - -

CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:45:42
Last modifiedWednesday, 24 January 2024 08:53:55
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
User risk
IncludeHigh
Sign-in risk
IncludeHigh
Grant
Control access enforcement to block or grant access.Block access
- - -

CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 10:06:50
Last modifiedWednesday, 3 January 2024 09:54:21
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Device platform
IncludeWindows
macOS
Filter for devices
Exclude filtered devices from policydevice.deviceOwnership -eq "Company" -or device.isCompliant -eq True
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Sign-in frequency12 hours
- - -

CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:30:47
Last modifiedTuesday, 2 January 2024 10:39:07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeMicrosoft Intune Enrollment
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
Session
Sign-in frequencyEvery time
- - -

CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:32:55
Last modifiedTuesday, 2 January 2024 10:39:24
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Conditions
Device platform
IncludeAny device
ExcludeAndroid
iOS
Windows
macOS
Grant
Control access enforcement to block or grant access.Block access
- - - -

CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration

- - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
Profile typeConditional Access
Enable policyOn
CreatedWednesday, 3 January 2024 08:08:24
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration - Exclude
Cloud apps or actions
Cloud apps
IncludeNone
Grant
Control access enforcement to block or grant access.Grant access
Require device to be marked as compliantEnabled
Require Microsoft Entra hybrid joined deviceEnabled
For multiple controlsRequire one of the selected controls
- -

CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:27:49
Last modifiedWednesday, 3 January 2024 09:52:28
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Users and groupsAPP_Microsoft365_E5_Dev
Exclude
Users and groupsCA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
ExcludeMicrosoft Intune Enrollment
Conditions
Device platform
IncludeWindows
Grant
Control access enforcement to block or grant access.Grant access
Require device to be marked as compliantEnabled
Require Microsoft Entra hybrid joined deviceEnabled
For multiple controlsRequire one of the selected controls
- -

CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 07:23:41
Last modifiedTuesday, 2 January 2024 10:52:19
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Exclude
Users and groupsCA-BreakGlassAccounts - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
Require multifactor authenticationEnabled
For multiple controlsRequire one of the selected controls
- - -

CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:37:47
Last modifiedWednesday, 27 March 2024 15:06:48
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Exclude
Users and groupsCA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
ExcludeMy Apps
Office365
Grant
Control access enforcement to block or grant access.Block access
- - -

CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameCA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile typeConditional Access
Enable policyOn
CreatedTuesday, 2 January 2024 09:55:02
Last modifiedTuesday, 2 January 2024 10:39:39
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Users and groups
Include
IncludeSelect users and groups
Exclude
Users and groupsCA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
IncludeAll cloud apps
Grant
Control access enforcement to block or grant access.Grant access
For multiple controlsRequire all the selected controls
Session
Sign-in frequency12 hours
- - -

Named Locations

-

ALLOWED COUNTRIES

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameValue
Basics
NameALLOWED COUNTRIES
Description
Profile typeNamed locations
CreatedWednesday, 7 September 2022 13:48:18
Last modifiedFriday, 3 February 2023 08:18:30
- - - - - - - - - - - - - - - - - - - -
NameValue
Country lookup methodDetermine location by IP address (IPv4 and IPv6)
Include unknown countries/regionsDisabled
Countries

+## Named locations +## Importing the baseline \ No newline at end of file