mirror of
https://github.com/j0eyv/ConditionalAccessBaseline.git
synced 2026-09-28 18:35:38 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c2391c3479 | ||
|
|
fef9253c24 | ||
|
|
67c82f5d55 | ||
|
|
38469a4faf | ||
|
|
7c0712003a | ||
|
|
c18b4e9df0 | ||
|
|
4a02a0f5c0 | ||
|
|
ba7ee267ff | ||
|
|
fb2921aa96 | ||
|
|
46f734ade5 | ||
|
|
e0781cbd2a | ||
|
|
43cb19ab14 |
@@ -0,0 +1,2 @@
|
|||||||
|
.package-sync/
|
||||||
|
.tmp/
|
||||||
BIN
Binary file not shown.
+162
@@ -0,0 +1,162 @@
|
|||||||
|
{
|
||||||
|
"@odata.context": "https://graph.microsoft.com/beta/$metadata#identity/conditionalAccess/policies/$entity",
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessPolicy",
|
||||||
|
"@odata.id": "identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)",
|
||||||
|
"@odata.editLink": "identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)",
|
||||||
|
"id": "4192875f-8b4c-4bc6-b797-f7629f71c709",
|
||||||
|
"templateId": null,
|
||||||
|
"displayName": "CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-AppEnforcedRestrictions",
|
||||||
|
"createdDateTime@odata.type": "#DateTimeOffset",
|
||||||
|
"createdDateTime": "2026-02-13T13:21:01.0192067Z",
|
||||||
|
"modifiedDateTime@odata.type": "#DateTimeOffset",
|
||||||
|
"modifiedDateTime": "2026-02-13T13:28:15.6527415Z",
|
||||||
|
"state@odata.type": "#microsoft.graph.conditionalAccessPolicyState",
|
||||||
|
"state": "enabled",
|
||||||
|
"deletedDateTime": null,
|
||||||
|
"partialEnablementStrategy": null,
|
||||||
|
"conditions": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessConditionSet",
|
||||||
|
"userRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
|
||||||
|
"userRiskLevels": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"signInRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
|
||||||
|
"signInRiskLevels": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"clientAppTypes@odata.type": "#Collection(microsoft.graph.conditionalAccessClientApp)",
|
||||||
|
"clientAppTypes": [
|
||||||
|
"browser",
|
||||||
|
"mobileAppsAndDesktopClients"
|
||||||
|
],
|
||||||
|
"locations": null,
|
||||||
|
"times": null,
|
||||||
|
"deviceStates": null,
|
||||||
|
"clientApplications": null,
|
||||||
|
"agents": null,
|
||||||
|
"applications": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessApplications",
|
||||||
|
"includeApplications@odata.type": "#Collection(String)",
|
||||||
|
"includeApplications": [
|
||||||
|
"Office365"
|
||||||
|
],
|
||||||
|
"excludeApplications@odata.type": "#Collection(String)",
|
||||||
|
"excludeApplications": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"includeUserActions@odata.type": "#Collection(String)",
|
||||||
|
"includeUserActions": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"includeAuthenticationContextClassReferences@odata.type": "#Collection(String)",
|
||||||
|
"includeAuthenticationContextClassReferences": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"applicationFilter": null
|
||||||
|
},
|
||||||
|
"users": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessUsers",
|
||||||
|
"includeUsers@odata.type": "#Collection(String)",
|
||||||
|
"includeUsers": [
|
||||||
|
"All"
|
||||||
|
],
|
||||||
|
"excludeUsers@odata.type": "#Collection(String)",
|
||||||
|
"excludeUsers": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"includeGroups@odata.type": "#Collection(String)",
|
||||||
|
"includeGroups": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"excludeGroups@odata.type": "#Collection(String)",
|
||||||
|
"excludeGroups": [
|
||||||
|
"2802b872-ccfb-4b29-a9a9-459808dfb11b",
|
||||||
|
"20cd89e3-25e2-4fcd-82c5-de666dfd31a4"
|
||||||
|
],
|
||||||
|
"includeRoles@odata.type": "#Collection(String)",
|
||||||
|
"includeRoles": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"excludeRoles@odata.type": "#Collection(String)",
|
||||||
|
"excludeRoles": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"includeGuestsOrExternalUsers": null,
|
||||||
|
"excludeGuestsOrExternalUsers": null
|
||||||
|
},
|
||||||
|
"platforms": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessPlatforms",
|
||||||
|
"includePlatforms@odata.type": "#Collection(microsoft.graph.conditionalAccessDevicePlatform)",
|
||||||
|
"includePlatforms": [
|
||||||
|
"android",
|
||||||
|
"iOS"
|
||||||
|
],
|
||||||
|
"excludePlatforms@odata.type": "#Collection(microsoft.graph.conditionalAccessDevicePlatform)",
|
||||||
|
"excludePlatforms": [
|
||||||
|
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"devices": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessDevices",
|
||||||
|
"includeDeviceStates@odata.type": "#Collection(String)",
|
||||||
|
"includeDeviceStates": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"excludeDeviceStates@odata.type": "#Collection(String)",
|
||||||
|
"excludeDeviceStates": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"includeDevices@odata.type": "#Collection(String)",
|
||||||
|
"includeDevices": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"excludeDevices@odata.type": "#Collection(String)",
|
||||||
|
"excludeDevices": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"deviceFilter": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessFilter",
|
||||||
|
"mode@odata.type": "#microsoft.graph.filterMode",
|
||||||
|
"mode": "exclude",
|
||||||
|
"rule": "device.isCompliant -eq True -and device.deviceOwnership -eq \"Company\""
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"grantControls": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessGrantControls",
|
||||||
|
"operator": "OR",
|
||||||
|
"builtInControls@odata.type": "#Collection(microsoft.graph.conditionalAccessGrantControl)",
|
||||||
|
"builtInControls": [
|
||||||
|
"compliantApplication"
|
||||||
|
],
|
||||||
|
"customAuthenticationFactors@odata.type": "#Collection(String)",
|
||||||
|
"customAuthenticationFactors": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"termsOfUse@odata.type": "#Collection(String)",
|
||||||
|
"termsOfUse": [
|
||||||
|
|
||||||
|
],
|
||||||
|
"authenticationStrength@odata.context": "https://graph.microsoft.com/beta/$metadata#identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/grantControls/authenticationStrength/$entity",
|
||||||
|
"authenticationStrength@odata.associationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/grantControls/authenticationStrength/$ref",
|
||||||
|
"authenticationStrength@odata.navigationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/grantControls/authenticationStrength",
|
||||||
|
"authenticationStrength": null
|
||||||
|
},
|
||||||
|
"sessionControls": {
|
||||||
|
"@odata.type": "#microsoft.graph.conditionalAccessSessionControls",
|
||||||
|
"disableResilienceDefaults": null,
|
||||||
|
"cloudAppSecurity": null,
|
||||||
|
"signInFrequency": null,
|
||||||
|
"persistentBrowser": null,
|
||||||
|
"continuousAccessEvaluation": null,
|
||||||
|
"secureSignInSession": null,
|
||||||
|
"applicationEnforcedRestrictions": {
|
||||||
|
"@odata.type": "#microsoft.graph.applicationEnforcedRestrictionsSessionControl",
|
||||||
|
"isEnabled": true
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"#microsoft.graph.restore": {
|
||||||
|
"title": "microsoft.graph.restore",
|
||||||
|
"target": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/microsoft.graph.restore"
|
||||||
|
}
|
||||||
|
}
|
||||||
BIN
Binary file not shown.
BIN
Binary file not shown.
BIN
Binary file not shown.
BIN
Binary file not shown.
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 661 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 1.0 MiB |
@@ -35,7 +35,7 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
- [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#ca002-global-identityprotection-anyapp-anyplatform-block-legacyauthentication)
|
- [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#ca002-global-identityprotection-anyapp-anyplatform-block-legacyauthentication)
|
||||||
- [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#ca003-global-baseprotection-registerorjoin-anyplatform-mfa)
|
- [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#ca003-global-baseprotection-registerorjoin-anyplatform-mfa)
|
||||||
- [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#ca004-global-identityprotection-anyapp-anyplatform-authenticationflows)
|
- [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#ca004-global-identityprotection-anyapp-anyplatform-authenticationflows)
|
||||||
- [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection](#ca005-global-dataprotection-office365-anyplatform-unmanaged-requireappprotection)
|
- [CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-AppEnforcedRestrictions](#ca005-global-dataprotection-office365-iosenandroid-clientapps-unmanaged-appenforcedrestrictions)
|
||||||
- [CA006-Global-DataProtection-Office365-iOSenAndroid-RequireAppProtection](#ca006-global-dataprotection-office365-iosenandroid-requireappprotection)
|
- [CA006-Global-DataProtection-Office365-iOSenAndroid-RequireAppProtection](#ca006-global-dataprotection-office365-iosenandroid-requireappprotection)
|
||||||
- [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#ca100-admins-identityprotection-adminportals-anyplatform-mfa)
|
- [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#ca100-admins-identityprotection-adminportals-anyplatform-mfa)
|
||||||
- [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca101-admins-identityprotection-anyapp-anyplatform-mfa)
|
- [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca101-admins-identityprotection-anyapp-anyplatform-mfa)
|
||||||
@@ -59,8 +59,8 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
- [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa)
|
- [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa)
|
||||||
- [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#ca401-guestusers-attacksurfacereduction-allapps-anyplatform-blocknonguestappaccess)
|
- [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#ca401-guestusers-attacksurfacereduction-allapps-anyplatform-blocknonguestappaccess)
|
||||||
- [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca402-guestusers-identityprotection-allapps-anyplatform-signinfrequency)
|
- [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca402-guestusers-identityprotection-allapps-anyplatform-signinfrequency)
|
||||||
- [CA403-Guests-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser](#ca403-guests-identityprotection-allapps-anyplatform-persistentbrowser)
|
- [CA403-GuestUsers-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser](#ca403-guestusers-identityprotection-allapps-anyplatform-persistentbrowser)
|
||||||
- [CA404-Guests-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca404-guests-attacksurfacereduction-selectedapps-anyplatform-block)
|
- [CA404-GuestUsers-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca404-guestusers-attacksurfacereduction-selectedapps-anyplatform-block)
|
||||||
- [CA501-Agents-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskAgent](#ca501-agents-identityprotection-anyapp-anyplatform-block-highriskagent)
|
- [CA501-Agents-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskAgent](#ca501-agents-identityprotection-anyapp-anyplatform-block-highriskagent)
|
||||||
- [CA502-Agents-AttackSurfaceReduction-AllAgentIdentities-AllAgentResources-BLOCK](#ca502-agents-attacksurfacereduction-allagentidentities-allagentresources-block)
|
- [CA502-Agents-AttackSurfaceReduction-AllAgentIdentities-AllAgentResources-BLOCK](#ca502-agents-attacksurfacereduction-allagentidentities-allagentresources-block)
|
||||||
- [CA503-Agents-BaseProtection-AllAgentUsers-AllResources-RequireCompliantDevice](#ca503-agents-baseprotection-allagentusers-allresources-requirecompliantdevice)
|
- [CA503-Agents-BaseProtection-AllAgentUsers-AllResources-RequireCompliantDevice](#ca503-agents-baseprotection-allagentusers-allresources-requirecompliantdevice)
|
||||||
@@ -70,8 +70,10 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
|
|||||||
- [Considerations](#considerations)
|
- [Considerations](#considerations)
|
||||||
- [Troubleshooting](#troubleshooting)
|
- [Troubleshooting](#troubleshooting)
|
||||||
- [Importing the baseline](#importing-the-baseline)
|
- [Importing the baseline](#importing-the-baseline)
|
||||||
- [Setup IntuneManagement](#setup-intunemanagement)
|
- [Option 1 - ConditionalAccessBaseline Importer](#option-1---conditionalaccessbaseline-importer)
|
||||||
- [Import the configuration](#import-the-configuration)
|
- [Option 2 - IntuneManagementTool](#option-2---intunemanagementtool)
|
||||||
|
- [Setup IntuneManagement](#setup-intunemanagement)
|
||||||
|
- [Import the configuration](#import-the-configuration)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -213,9 +215,9 @@ This policy prevents all users from transfering authentication flows from PC to
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection
|
### CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-AppEnforcedRestrictions
|
||||||
|
|
||||||
This policyrequires App Protection Policies on unmanaged devices.
|
This policyrequires App Enforced Restrictions on unmanaged devices.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@@ -420,13 +422,13 @@ This policy sets a Sign-in frequency to a maximum of 12 hours for guests, to all
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
### CA403-Guests-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser
|
### CA403-GuestUsers-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser
|
||||||
|
|
||||||
This policy prevents guest from having persistent browser sessions.
|
This policy prevents guest from having persistent browser sessions.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
### CA404-Guests-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK
|
### CA404-GuestUsers-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK
|
||||||
|
|
||||||
This policy prevents guests from accessing specific apps. In this example i've blocked a random app. You should review the included and excluded apps. Excluding office 365 is not necessary if its not included. This is just an example.
|
This policy prevents guests from accessing specific apps. In this example i've blocked a random app. You should review the included and excluded apps. Excluding office 365 is not necessary if its not included. This is just an example.
|
||||||
|
|
||||||
@@ -485,6 +487,26 @@ Learn more: https://learn.microsoft.com/en-us/entra/identity/conditional-access/
|
|||||||
|
|
||||||
## Importing the baseline
|
## Importing the baseline
|
||||||
|
|
||||||
|
### Option 1 - ConditionalAccessBaseline Importer
|
||||||
|
|
||||||
|
|
||||||
|
> [!Note]
|
||||||
|
> The tool is intended as a simple, one-time deployment method. After deploying the baseline, consider removing the Enterprise App from your tenant. If you prefer an offline deployment method choose option 2 instead. Please keep in mind that this is a web app and use it on your own risk.
|
||||||
|
|
||||||
|
* **Step 1**: Open the Conditional Access web app: https://conditionalaccess.joeyverlinden.com/.
|
||||||
|
* **Step 2**: Click **Deploy Conditional Access Baseline**.
|
||||||
|
* **Step 3**: Sign in with an Entra ID account that has sufficient permissions (for example, Conditional Access Administrator). Grant approval for the necessary permissions.
|
||||||
|
* **Step 4**: Select the policies you want to deploy. If you are applying updates, select only the updated policies (see changelog). For a new implementation, select all policies.
|
||||||
|
* **Step 5**: Click **Deploy Baseline**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
After deployment is completed, all policies are available in the Entra ID Admin Center and Azure portal.
|
||||||
|
|
||||||
|
### Option 2 - IntuneManagementTool
|
||||||
|
|
||||||
These PowerShell scripts are using Microsoft Authentication Library (MSAL), Microsoft Graph APIs and Azure Management APIs to manage objects in Intune and Azure. The scripts has a simple WPF UI and it supports operations like Export, Import, Copy, Download, Compare etc.
|
These PowerShell scripts are using Microsoft Authentication Library (MSAL), Microsoft Graph APIs and Azure Management APIs to manage objects in Intune and Azure. The scripts has a simple WPF UI and it supports operations like Export, Import, Copy, Download, Compare etc.
|
||||||
|
|
||||||
This makes it easy to backup or clone a complete Intune environment. The scripts can export and import objects including assignments and support import/export between tenants. The scripts will create a migration table during export and use that for importing assignments in other environments. It will create missing groups in the target environment during import. Group information like name, description and type will be imported based on the exported group e.g. dynamic groups are supported. There will be one json file for each group in the export folder.
|
This makes it easy to backup or clone a complete Intune environment. The scripts can export and import objects including assignments and support import/export between tenants. The scripts will create a migration table during export and use that for importing assignments in other environments. It will create missing groups in the target environment during import. Group information like name, description and type will be imported based on the exported group e.g. dynamic groups are supported. There will be one json file for each group in the export folder.
|
||||||
@@ -496,7 +518,7 @@ The script also support dependencies e.g. an App Protection is depending on an A
|
|||||||
> [!TIP]
|
> [!TIP]
|
||||||
> The following tool is used: https://github.com/Micke-K/IntuneManagement. Always download the lastest version before importing or exporting data.
|
> The following tool is used: https://github.com/Micke-K/IntuneManagement. Always download the lastest version before importing or exporting data.
|
||||||
|
|
||||||
### Setup IntuneManagement
|
#### Setup IntuneManagement
|
||||||
|
|
||||||
Start by downloading the files in GitHub. Extract the Github repo somewhere on your device. For example: *C:\Intune\IntuneManagement*.
|
Start by downloading the files in GitHub. Extract the Github repo somewhere on your device. For example: *C:\Intune\IntuneManagement*.
|
||||||
|
|
||||||
@@ -536,7 +558,7 @@ Go ahead and accept the popup again, this should clear all the red text on the l
|
|||||||
|
|
||||||
Now we can start importing, exporting, or comparing tenant configurations.
|
Now we can start importing, exporting, or comparing tenant configurations.
|
||||||
|
|
||||||
### Import the configuration
|
#### Import the configuration
|
||||||
|
|
||||||
1: Click on **Bulk** -> **Import**
|
1: Click on **Bulk** -> **Import**
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user