12 Commits
Author SHA1 Message Date
Joey vldn c2391c3479 Update README.md 2026-08-12 09:02:01 +02:00
Joey vldn fef9253c24 Update ConditionalAccessBaseline Importer section
Updated ConditionalAccessBaseline Importer section
2026-08-12 08:57:36 +02:00
j0eyv 67c82f5d55 Fixed TYPO policy 403 / 404
Fixed TYPO policy 403 / 404
2026-07-22 12:48:39 +02:00
j0eyv 38469a4faf Update - Importing methods
Update - Importing methods
2026-07-17 15:04:31 +02:00
Joey vldn 7c0712003a Delete Config/ConditionalAccess/CA006-Global-DataProtection-Office365-iOSenAndroid-RequireAppProtection.json 2026-07-13 14:35:49 +02:00
Joey vldn c18b4e9df0 Update and rename CA007-Global-DataProtection-Office365-AnyPlatform-Browser-Unmanaged-AppEnforceRestrictions.json to CA006-Global-DataProtection-Office365-AnyPlatform-Browser-Unmanaged-AppEnforceRestrictions.json 2026-07-13 14:35:29 +02:00
Joey vldn 4a02a0f5c0 Add CA007 configuration for data protection 2026-07-13 14:34:08 +02:00
Joey vldn ba7ee267ff Rename conditional access policy CA006 to CA007
Updated the display name of the conditional access policy from 'CA006' to 'CA007'.
2026-07-13 14:33:53 +02:00
j0eyv fb2921aa96 Modify readme 2026-07-03 09:41:59 +02:00
Joey vldn 46f734ade5 Update and rename CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection.json to CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-AppEnforcedRestrictions.json 2026-07-03 09:38:52 +02:00
Joey vldn e0781cbd2a Update MigrationTable.json 2026-07-03 09:38:48 +02:00
Joey vldn 43cb19ab14 Update CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-RequireAppProtection - Exclude.json 2026-07-03 09:38:44 +02:00
11 changed files with 197 additions and 11 deletions
+2
View File
@@ -0,0 +1,2 @@
.package-sync/
.tmp/
@@ -0,0 +1,162 @@
{
"@odata.context": "https://graph.microsoft.com/beta/$metadata#identity/conditionalAccess/policies/$entity",
"@odata.type": "#microsoft.graph.conditionalAccessPolicy",
"@odata.id": "identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)",
"@odata.editLink": "identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)",
"id": "4192875f-8b4c-4bc6-b797-f7629f71c709",
"templateId": null,
"displayName": "CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-AppEnforcedRestrictions",
"createdDateTime@odata.type": "#DateTimeOffset",
"createdDateTime": "2026-02-13T13:21:01.0192067Z",
"modifiedDateTime@odata.type": "#DateTimeOffset",
"modifiedDateTime": "2026-02-13T13:28:15.6527415Z",
"state@odata.type": "#microsoft.graph.conditionalAccessPolicyState",
"state": "enabled",
"deletedDateTime": null,
"partialEnablementStrategy": null,
"conditions": {
"@odata.type": "#microsoft.graph.conditionalAccessConditionSet",
"userRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
"userRiskLevels": [
],
"signInRiskLevels@odata.type": "#Collection(microsoft.graph.riskLevel)",
"signInRiskLevels": [
],
"clientAppTypes@odata.type": "#Collection(microsoft.graph.conditionalAccessClientApp)",
"clientAppTypes": [
"browser",
"mobileAppsAndDesktopClients"
],
"locations": null,
"times": null,
"deviceStates": null,
"clientApplications": null,
"agents": null,
"applications": {
"@odata.type": "#microsoft.graph.conditionalAccessApplications",
"includeApplications@odata.type": "#Collection(String)",
"includeApplications": [
"Office365"
],
"excludeApplications@odata.type": "#Collection(String)",
"excludeApplications": [
],
"includeUserActions@odata.type": "#Collection(String)",
"includeUserActions": [
],
"includeAuthenticationContextClassReferences@odata.type": "#Collection(String)",
"includeAuthenticationContextClassReferences": [
],
"applicationFilter": null
},
"users": {
"@odata.type": "#microsoft.graph.conditionalAccessUsers",
"includeUsers@odata.type": "#Collection(String)",
"includeUsers": [
"All"
],
"excludeUsers@odata.type": "#Collection(String)",
"excludeUsers": [
],
"includeGroups@odata.type": "#Collection(String)",
"includeGroups": [
],
"excludeGroups@odata.type": "#Collection(String)",
"excludeGroups": [
"2802b872-ccfb-4b29-a9a9-459808dfb11b",
"20cd89e3-25e2-4fcd-82c5-de666dfd31a4"
],
"includeRoles@odata.type": "#Collection(String)",
"includeRoles": [
],
"excludeRoles@odata.type": "#Collection(String)",
"excludeRoles": [
],
"includeGuestsOrExternalUsers": null,
"excludeGuestsOrExternalUsers": null
},
"platforms": {
"@odata.type": "#microsoft.graph.conditionalAccessPlatforms",
"includePlatforms@odata.type": "#Collection(microsoft.graph.conditionalAccessDevicePlatform)",
"includePlatforms": [
"android",
"iOS"
],
"excludePlatforms@odata.type": "#Collection(microsoft.graph.conditionalAccessDevicePlatform)",
"excludePlatforms": [
]
},
"devices": {
"@odata.type": "#microsoft.graph.conditionalAccessDevices",
"includeDeviceStates@odata.type": "#Collection(String)",
"includeDeviceStates": [
],
"excludeDeviceStates@odata.type": "#Collection(String)",
"excludeDeviceStates": [
],
"includeDevices@odata.type": "#Collection(String)",
"includeDevices": [
],
"excludeDevices@odata.type": "#Collection(String)",
"excludeDevices": [
],
"deviceFilter": {
"@odata.type": "#microsoft.graph.conditionalAccessFilter",
"mode@odata.type": "#microsoft.graph.filterMode",
"mode": "exclude",
"rule": "device.isCompliant -eq True -and device.deviceOwnership -eq \"Company\""
}
}
},
"grantControls": {
"@odata.type": "#microsoft.graph.conditionalAccessGrantControls",
"operator": "OR",
"builtInControls@odata.type": "#Collection(microsoft.graph.conditionalAccessGrantControl)",
"builtInControls": [
"compliantApplication"
],
"customAuthenticationFactors@odata.type": "#Collection(String)",
"customAuthenticationFactors": [
],
"termsOfUse@odata.type": "#Collection(String)",
"termsOfUse": [
],
"authenticationStrength@odata.context": "https://graph.microsoft.com/beta/$metadata#identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/grantControls/authenticationStrength/$entity",
"authenticationStrength@odata.associationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/grantControls/authenticationStrength/$ref",
"authenticationStrength@odata.navigationLink": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/grantControls/authenticationStrength",
"authenticationStrength": null
},
"sessionControls": {
"@odata.type": "#microsoft.graph.conditionalAccessSessionControls",
"disableResilienceDefaults": null,
"cloudAppSecurity": null,
"signInFrequency": null,
"persistentBrowser": null,
"continuousAccessEvaluation": null,
"secureSignInSession": null,
"applicationEnforcedRestrictions": {
"@odata.type": "#microsoft.graph.applicationEnforcedRestrictionsSessionControl",
"isEnabled": true
}
},
"#microsoft.graph.restore": {
"title": "microsoft.graph.restore",
"target": "https://graph.microsoft.com/beta/identity/conditionalAccess/policies(\u00274192875f-8b4c-4bc6-b797-f7629f71c709\u0027)/microsoft.graph.restore"
}
}
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 661 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.0 MiB

+31 -9
View File
@@ -35,7 +35,7 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
- [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#ca002-global-identityprotection-anyapp-anyplatform-block-legacyauthentication)
- [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#ca003-global-baseprotection-registerorjoin-anyplatform-mfa)
- [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#ca004-global-identityprotection-anyapp-anyplatform-authenticationflows)
- [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection](#ca005-global-dataprotection-office365-anyplatform-unmanaged-requireappprotection)
- [CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-AppEnforcedRestrictions](#ca005-global-dataprotection-office365-iosenandroid-clientapps-unmanaged-appenforcedrestrictions)
- [CA006-Global-DataProtection-Office365-iOSenAndroid-RequireAppProtection](#ca006-global-dataprotection-office365-iosenandroid-requireappprotection)
- [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#ca100-admins-identityprotection-adminportals-anyplatform-mfa)
- [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca101-admins-identityprotection-anyapp-anyplatform-mfa)
@@ -59,8 +59,8 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
- [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#ca400-guestusers-identityprotection-anyapp-anyplatform-mfa)
- [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#ca401-guestusers-attacksurfacereduction-allapps-anyplatform-blocknonguestappaccess)
- [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#ca402-guestusers-identityprotection-allapps-anyplatform-signinfrequency)
- [CA403-Guests-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser](#ca403-guests-identityprotection-allapps-anyplatform-persistentbrowser)
- [CA404-Guests-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca404-guests-attacksurfacereduction-selectedapps-anyplatform-block)
- [CA403-GuestUsers-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser](#ca403-guestusers-identityprotection-allapps-anyplatform-persistentbrowser)
- [CA404-GuestUsers-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK](#ca404-guestusers-attacksurfacereduction-selectedapps-anyplatform-block)
- [CA501-Agents-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRiskAgent](#ca501-agents-identityprotection-anyapp-anyplatform-block-highriskagent)
- [CA502-Agents-AttackSurfaceReduction-AllAgentIdentities-AllAgentResources-BLOCK](#ca502-agents-attacksurfacereduction-allagentidentities-allagentresources-block)
- [CA503-Agents-BaseProtection-AllAgentUsers-AllResources-RequireCompliantDevice](#ca503-agents-baseprotection-allagentusers-allresources-requirecompliantdevice)
@@ -70,6 +70,8 @@ This conditional access baseline is based on the Microsoft Conditional Access Ba
- [Considerations](#considerations)
- [Troubleshooting](#troubleshooting)
- [Importing the baseline](#importing-the-baseline)
- [Option 1 - ConditionalAccessBaseline Importer](#option-1---conditionalaccessbaseline-importer)
- [Option 2 - IntuneManagementTool](#option-2---intunemanagementtool)
- [Setup IntuneManagement](#setup-intunemanagement)
- [Import the configuration](#import-the-configuration)
@@ -213,9 +215,9 @@ This policy prevents all users from transfering authentication flows from PC to
![CA004](./Images/CA004.png)
### CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-RequireAppProtection
### CA005-Global-DataProtection-Office365-iOSenAndroid-ClientApps-Unmanaged-AppEnforcedRestrictions
This policyrequires App Protection Policies on unmanaged devices.
This policyrequires App Enforced Restrictions on unmanaged devices.
![CA005](./Images/CA005.png)
@@ -420,13 +422,13 @@ This policy sets a Sign-in frequency to a maximum of 12 hours for guests, to all
![CA402](./Images/CA402.png)
### CA403-Guests-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser
### CA403-GuestUsers-IdentityProtection-AllApps-AnyPlatform-PersistentBrowser
This policy prevents guest from having persistent browser sessions.
![CA403](./Images/CA403.png)
### CA404-Guests-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK
### CA404-GuestUsers-AttackSurfaceReduction-SelectedApps-AnyPlatform-BLOCK
This policy prevents guests from accessing specific apps. In this example i've blocked a random app. You should review the included and excluded apps. Excluding office 365 is not necessary if its not included. This is just an example.
@@ -485,6 +487,26 @@ Learn more: https://learn.microsoft.com/en-us/entra/identity/conditional-access/
## Importing the baseline
### Option 1 - ConditionalAccessBaseline Importer
> [!Note]
> The tool is intended as a simple, one-time deployment method. After deploying the baseline, consider removing the Enterprise App from your tenant. If you prefer an offline deployment method choose option 2 instead. Please keep in mind that this is a web app and use it on your own risk.
* **Step 1**: Open the Conditional Access web app: https://conditionalaccess.joeyverlinden.com/.
* **Step 2**: Click **Deploy Conditional Access Baseline**.
* **Step 3**: Sign in with an Entra ID account that has sufficient permissions (for example, Conditional Access Administrator). Grant approval for the necessary permissions.
* **Step 4**: Select the policies you want to deploy. If you are applying updates, select only the updated policies (see changelog). For a new implementation, select all policies.
* **Step 5**: Click **Deploy Baseline**.
![Importer1](./Images/Importer1.png)
![Importer2](./Images/Importer2.png)
After deployment is completed, all policies are available in the Entra ID Admin Center and Azure portal.
### Option 2 - IntuneManagementTool
These PowerShell scripts are using Microsoft Authentication Library (MSAL), Microsoft Graph APIs and Azure Management APIs to manage objects in Intune and Azure. The scripts has a simple WPF UI and it supports operations like Export, Import, Copy, Download, Compare etc.
This makes it easy to backup or clone a complete Intune environment. The scripts can export and import objects including assignments and support import/export between tenants. The scripts will create a migration table during export and use that for importing assignments in other environments. It will create missing groups in the target environment during import. Group information like name, description and type will be imported based on the exported group e.g. dynamic groups are supported. There will be one json file for each group in the export folder.
@@ -496,7 +518,7 @@ The script also support dependencies e.g. an App Protection is depending on an A
> [!TIP]
> The following tool is used: https://github.com/Micke-K/IntuneManagement. Always download the lastest version before importing or exporting data.
### Setup IntuneManagement
#### Setup IntuneManagement
Start by downloading the files in GitHub. Extract the Github repo somewhere on your device. For example: *C:\Intune\IntuneManagement*.
@@ -536,7 +558,7 @@ Go ahead and accept the popup again, this should clear all the red text on the l
Now we can start importing, exporting, or comparing tenant configurations.
### Import the configuration
#### Import the configuration
1: Click on **Bulk** -> **Import**