56 KiB
Conditional Access Baseline
This conditional access baseline is based on the Microsoft Conditional Access Baseline by Claus Jespersen. This one is slightly minimized and less dificult to understand but still protects almost everything you could wish for. Use this baseline to start off with and expend where needed.
Resources
➡ Microsoft Learn: https://learn.microsoft.com/en-us/azure/architecture/guide/security/conditional-access-framework
➡ Framework documentation by Claus Jespersen: https://github.com/microsoft/ConditionalAccessforZeroTrustResources/blob/main/ConditionalAccessGovernanceAndPrinciplesforZeroTrust%20October%202023.pdf
➡ Framework resources: https://github.com/microsoft/ConditionalAccessforZeroTrustResources
Table of Contents
-
-
-
CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
-
CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
-
CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
-
CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
-
CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
-
CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
-
CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
-
CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
-
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
-
CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
-
CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
-
CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
-
CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
-
CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
-
Conditional access
Conditional access policies
CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Basics | |
| Name | CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:47:07 |
| Last modified | Wednesday, 27 March 2024 14:41:39 |
Table 1. Basics - CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Directory roles | Directory Synchronization Accounts |
| Users and groups | CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - ExcludeCA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
Table 2. Settings - CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
| Name | Value |
| Basics | |
| Name | CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 08:02:06 |
| Last modified | Tuesday, 2 January 2024 10:38:04 |
Table 3. Basics - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Locations | |
| Include | Any location |
| Exclude | ALLOWED COUNTRIES |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
Table 4. Settings - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
| Name | Value |
| Basics | |
| Name | CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:08:14 |
| Last modified | Tuesday, 2 January 2024 10:38:10 |
Table 5. Basics - CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Client apps | |
| Include | Exchange ActiveSync Other clients |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
Table 6. Settings - CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
| Name | Value |
| Basics | |
| Name | CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 3 January 2024 07:52:15 |
Table 7. Basics - CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| User actions | |
| Select the action this policy will apply to | Register or join devices |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
Table 8. Settings - CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
| Name | Value |
| Basics | |
| Name | CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 27 March 2024 14:28:00 |
| Last modified | Monday, 8 April 2024 12:38:51 |
Table 9. Basics - CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
Table 10. Settings - CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
| Name | Value |
| Basics | |
| Name | CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 27 March 2024 14:40:41 |
| Last modified | Monday, 8 April 2024 12:38:39 |
Table 11. Basics - CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
| Name | Value |
| Users and groups | |
| Include | |
| Include | All users |
| Exclude | |
| Users and groups | CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | Office 365 Exchange Online Office 365 SharePoint Online |
| Conditions | |
| Client apps | |
| Include | Browser |
| Filter for devices | |
| Exclude filtered devices from policy | device.isCompliant -eq True |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Use app enforced restrictions | Enabled |
Table 12. Settings - CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
| Name | Value |
| Basics | |
| Name | CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Friday, 22 December 2023 10:12:23 |
| Last modified | Wednesday, 3 January 2024 09:43:35 |
Table 13. Basics - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Directory roles | Global AdministratorSecurity Administrator SharePoint Administrator Exchange Administrator Conditional Access Administrator Helpdesk Administrator Billing Administrator User Administrator Authentication Administrator Application Administrator Cloud Application Administrator Password Administrator Privileged Authentication Administrator Privileged Role Administrator |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | MicrosoftAdminPortals |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Authentication strength | |
| For multiple controls | Require one of the selected controls |
Table 14. Settings - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Basics | |
| Name | CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Monday, 31 January 2022 16:44:43 |
| Last modified | Tuesday, 2 January 2024 10:38:19 |
Table 15. Basics - CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Directory roles | Exchange AdministratorSecurity Administrator Conditional Access Administrator SharePoint Administrator Helpdesk Administrator Billing Administrator User Administrator Authentication Administrator Global Administrator Global Reader Intune Administrator |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Locations | |
| Include | Any location |
| Client apps | |
| Include | Exchange ActiveSync Browser Mobile apps and desktop clients Other clients |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
Table 16. Settings - CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
| Name | Value |
| Basics | |
| Name | CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 10:02:19 |
| Last modified | Tuesday, 2 January 2024 10:38:23 |
Table 17. Basics - CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Directory roles | Authentication AdministratorBilling Administrator Conditional Access Administrator Exchange Administrator Global Administrator Global Reader Helpdesk Administrator Intune Administrator Security Administrator User Administrator SharePoint Administrator |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Sign-in frequency | 12 hours |
Table 18. Settings - CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Basics | |
| Name | CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Monday, 31 January 2022 16:44:44 |
| Last modified | Tuesday, 2 January 2024 14:10:23 |
Table 19. Basics - CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Locations | |
| Include | Any location |
| Client apps | |
| Include | Browser Mobile apps and desktop clients |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
Table 20. Settings - CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
| Name | Value |
| Basics | |
| Name | CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:45:42 |
| Last modified | Wednesday, 24 January 2024 08:53:55 |
Table 21. Basics - CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| User risk | |
| Include | High |
| Sign-in risk | |
| Include | High |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
Table 22. Settings - CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
| Name | Value |
| Basics | |
| Name | CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 10:06:50 |
| Last modified | Wednesday, 3 January 2024 09:54:21 |
Table 23. Basics - CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Device platform | |
| Include | Windows macOS |
| Filter for devices | |
| Exclude filtered devices from policy | device.deviceOwnership -eq "Company" -or device.isCompliant -eq True |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Sign-in frequency | 12 hours |
Table 24. Settings - CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
| Name | Value |
| Basics | |
| Name | CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:30:47 |
| Last modified | Tuesday, 2 January 2024 10:39:07 |
Table 25. Basics - CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | Microsoft Intune Enrollment |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
| Session | |
| Sign-in frequency | Every time |
Table 26. Settings - CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
| Name | Value |
| Basics | |
| Name | CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:32:55 |
| Last modified | Tuesday, 2 January 2024 10:39:24 |
Table 27. Basics - CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Conditions | |
| Device platform | |
| Include | Any device |
| Exclude | Android iOS Windows macOS |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
Table 28. Settings - CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
| Name | Value |
| Basics | |
| Name | CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Wednesday, 3 January 2024 08:08:24 |
Table 29. Basics - CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | None |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require device to be marked as compliant | Enabled |
| Require Microsoft Entra hybrid joined device | Enabled |
| For multiple controls | Require one of the selected controls |
Table 30. Settings - CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
| Name | Value |
| Basics | |
| Name | CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:27:49 |
| Last modified | Wednesday, 3 January 2024 09:52:28 |
Table 31. Basics - CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Users and groups | APP_Microsoft365_E5_Dev |
| Exclude | |
| Users and groups | CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Exclude | Microsoft Intune Enrollment |
| Conditions | |
| Device platform | |
| Include | Windows |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require device to be marked as compliant | Enabled |
| Require Microsoft Entra hybrid joined device | Enabled |
| For multiple controls | Require one of the selected controls |
Table 32. Settings - CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Basics | |
| Name | CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 07:23:41 |
| Last modified | Tuesday, 2 January 2024 10:52:19 |
Table 33. Basics - CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Exclude | |
| Users and groups | CA-BreakGlassAccounts - Exclude CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| Require multifactor authentication | Enabled |
| For multiple controls | Require one of the selected controls |
Table 34. Settings - CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
| Name | Value |
| Basics | |
| Name | CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:37:47 |
| Last modified | Wednesday, 27 March 2024 15:06:48 |
Table 35. Basics - CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Exclude | |
| Users and groups | CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Exclude | My Apps Office365 |
| Grant | |
| Control access enforcement to block or grant access. | Block access |
Table 36. Settings - CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
| Name | Value |
| Basics | |
| Name | CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency |
| Profile type | Conditional Access |
| Enable policy | On |
| Created | Tuesday, 2 January 2024 09:55:02 |
| Last modified | Tuesday, 2 January 2024 10:39:39 |
Table 37. Basics - CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
| Name | Value |
| Users and groups | |
| Include | |
| Include | Select users and groups |
| Exclude | |
| Users and groups | CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude CA-BreakGlassAccounts - Exclude |
| Cloud apps or actions | |
| Cloud apps | |
| Include | All cloud apps |
| Grant | |
| Control access enforcement to block or grant access. | Grant access |
| For multiple controls | Require all the selected controls |
| Session | |
| Sign-in frequency | 12 hours |
Table 38. Settings - CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Named Locations
ALLOWED COUNTRIES
| Name | Value |
| Basics | |
| Name | ALLOWED COUNTRIES |
| Description | |
| Profile type | Named locations |
| Created | Wednesday, 7 September 2022 13:48:18 |
| Last modified | Friday, 3 February 2023 08:18:30 |
Table 39. Basics - ALLOWED COUNTRIES
| Name | Value |
| Country lookup method | Determine location by IP address (IPv4 and IPv6) |
| Include unknown countries/regions | Disabled |
| Countries |