# Intune documentation *Organization:* m365jv *Generated by:* Joey Verlinden (Access@m365jv.onmicrosoft.com) *Generated:* 09/04/2024 15:43:22 ## Table of Contents - [Conditional access](#section-1) - [Conditional access policies](#section-2) - [CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-3) - [CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist](#section-4) - [CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication](#section-5) - [CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA](#section-6) - [CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows](#section-7) - [CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload](#section-8) - [CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA](#section-9) - [CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-10) - [CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#section-11) - [CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-12) - [CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk](#section-13) - [CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices](#section-14) - [CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA](#section-15) - [CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms](#section-16) - [CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration](#section-17) - [CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ](#section-18) - [CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA](#section-19) - [CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess](#section-20) - [CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency](#section-21) - [Named Locations](#section-22) - [ALLOWED COUNTRIES](#section-23)
| Name | Value |
| Basics | |
| Name | CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:47:07 |
| Last modified | Wednesday, 27 March 2024 14:41:39 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Directory roles | Directory Synchronization Accounts |
| Users and groups | CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - ExcludeCA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 08:02:06 |
| Last modified | Tuesday, 2 January 2024 10:38:04 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Locations | |
| Include | Any location |
| Exclude | ALLOWED COUNTRIES |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
| Name | Value |
| Basics | |
| Name | CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:08:14 |
| Last modified | Tuesday, 2 January 2024 10:38:10 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Client apps | |
| Include | Exchange ActiveSync Other clients |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
| Name | Value |
| Basics | |
| Name | CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 3 January 2024 07:52:15 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| User actions | |
| Select the action this policy will apply to | Register or join devices |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 27 March 2024 14:28:00 |
| Last modified | Monday, 8 April 2024 12:38:51 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
| Name | Value |
| Basics | |
| Name | CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 27 March 2024 14:40:41 |
| Last modified | Monday, 8 April 2024 12:38:39 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | Office 365 Exchange Online Office 365 SharePoint Online |
| Conditions | |
| Client apps | |
| Include | Browser |
| Filter for devices | |
| Exclude filtered devices from policy | device.isCompliant -eq True |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Use app enforced restrictions | Enabled |
| Name | Value |
| Basics | |
| Name | CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Friday, 22 December 2023 10:12:23 |
| Last modified | Wednesday, 3 January 2024 09:43:35 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Directory roles | Global AdministratorSecurity Administrator SharePoint Administrator Exchange Administrator Conditional Access Administrator Helpdesk Administrator Billing Administrator User Administrator Authentication Administrator Application Administrator Cloud Application Administrator Password Administrator Privileged Authentication Administrator Privileged Role Administrator |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | MicrosoftAdminPortals |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Authentication strength | |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Monday, 31 January 2022 16:44:43 |
| Last modified | Tuesday, 2 January 2024 10:38:19 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Directory roles | Exchange AdministratorSecurity Administrator Conditional Access Administrator SharePoint Administrator Helpdesk Administrator Billing Administrator User Administrator Authentication Administrator Global Administrator Global Reader Intune Administrator |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Locations | |
| Include | Any location |
| Client apps | |
| Include | Exchange ActiveSync Browser Mobile apps and desktop clients Other clients |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 10:02:19 |
| Last modified | Tuesday, 2 January 2024 10:38:23 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Directory roles | Authentication AdministratorBilling Administrator Conditional Access Administrator Exchange Administrator Global Administrator Global Reader Helpdesk Administrator Intune Administrator Security Administrator User Administrator SharePoint Administrator |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Sign-in frequency | 12 hours |
| Name | Value |
| Basics | |
| Name | CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Monday, 31 January 2022 16:44:44 |
| Last modified | Tuesday, 2 January 2024 14:10:23 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Locations | |
| Include | Any location |
| Client apps | |
| Include | Browser Mobile apps and desktop clients |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:45:42 |
| Last modified | Wednesday, 24 January 2024 08:53:55 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| User risk | |
| Include | High |
| Sign-in risk | |
| Include | High |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
| Name | Value |
| Basics | |
| Name | CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 10:06:50 |
| Last modified | Wednesday, 3 January 2024 09:54:21 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Device platform | |
| Include | Windows macOS |
| Filter for devices | |
| Exclude filtered devices from policy | device.deviceOwnership -eq "Company" -or device.isCompliant -eq True |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Sign-in frequency | 12 hours |
| Name | Value |
| Basics | |
| Name | CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:30:47 |
| Last modified | Tuesday, 2 January 2024 10:39:07 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | Microsoft Intune Enrollment |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
| Session | |
| Sign-in frequency | Every time |
| Name | Value |
| Basics | |
| Name | CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:32:55 |
| Last modified | Tuesday, 2 January 2024 10:39:24 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Device platform | |
| Include | Any device |
| Exclude | Android iOS Windows macOS |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
| Name | Value |
| Basics | |
| Name | CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 3 January 2024 08:08:24 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | None |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require device to be marked as compliant | Enabled |
| Require Microsoft Entra hybrid joined device | Enabled |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:27:49 |
| Last modified | Wednesday, 3 January 2024 09:52:28 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Exclude | Microsoft Intune Enrollment |
| Conditions | |
| Device platform | |
| Include | Windows |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require device to be marked as compliant | Enabled |
| Require Microsoft Entra hybrid joined device | Enabled |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:23:41 |
| Last modified | Tuesday, 2 January 2024 10:52:19 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
| Name | Value |
| Basics | |
| Name | CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:37:47 |
| Last modified | Wednesday, 27 March 2024 15:06:48 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Exclude | |
| Users and groups | CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Exclude | My Apps Office365 |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
| Name | Value |
| Basics | |
| Name | CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:55:02 |
| Last modified | Tuesday, 2 January 2024 10:39:39 |
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Exclude | |
| Users and groups | CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Sign-in frequency | 12 hours |
| Name | Value |
| Basics | |
| Name | ALLOWED COUNTRIES |
| Description | |
| Profile type | Named locations |
| Created | Wednesday, 7 September 2022 13:48:18 |
| Last modified | Friday, 3 February 2023 08:18:30 |
| Name | Value |
| Country lookup method | Determine location by IP address (IPv4 and IPv6) |
| Include unknown countries/regions | Disabled |
| Countries |