2024-04-09 15:47:27 +02:00
2024-04-09 14:53:44 +02:00
2024-04-09 15:47:27 +02:00

Table of Contents

Conditional access

Conditional access policies

CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:47:07
Last modified Wednesday, 27 March 2024 14:41:39
Table 1. Basics - CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
Name Value
Users and groups
Include
Include All users
Exclude
Directory roles Directory Synchronization Accounts
Users and groups
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls
Table 2. Settings - CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA

CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist

Name Value
Basics
Name CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 08:02:06
Last modified Tuesday, 2 January 2024 10:38:04
Table 3. Basics - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Locations
Include Any location
Exclude ALLOWED COUNTRIES
Grant
Control access enforcement to block or grant access. Block access
Table 4. Settings - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist

CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication

Name Value
Basics
Name CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:08:14
Last modified Tuesday, 2 January 2024 10:38:10
Table 5. Basics - CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Client apps
Include Exchange ActiveSync
Other clients
Grant
Control access enforcement to block or grant access. Block access
Table 6. Settings - CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication

CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA

Name Value
Basics
Name CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Wednesday, 3 January 2024 07:52:15
Table 7. Basics - CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA - Exclude
Cloud apps or actions
User actions
Select the action this policy will apply to Register or join devices
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls
Table 8. Settings - CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA

CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows

Name Value
Basics
Name CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
Profile type Conditional Access
Enable policy On
Created Wednesday, 27 March 2024 14:28:00
Last modified Monday, 8 April 2024 12:38:51
Table 9. Basics - CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Block access
Table 10. Settings - CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows

CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload

Name Value
Basics
Name CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
Profile type Conditional Access
Enable policy On
Created Wednesday, 27 March 2024 14:40:41
Last modified Monday, 8 April 2024 12:38:39
Table 11. Basics - CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include Office 365 Exchange Online
Office 365 SharePoint Online
Conditions
Client apps
Include Browser
Filter for devices
Exclude filtered devices from policy device.isCompliant -eq True
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Use app enforced restrictions Enabled
Table 12. Settings - CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload

CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA

Name Value
Basics
Name CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Friday, 22 December 2023 10:12:23
Last modified Wednesday, 3 January 2024 09:43:35
Table 13. Basics - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
Name Value
Users and groups
Include
Include Select users and groups
Directory roles
Global Administrator
Security Administrator
SharePoint Administrator
Exchange Administrator
Conditional Access Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Application Administrator
Cloud Application Administrator
Password Administrator
Privileged Authentication Administrator
Privileged Role Administrator
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include MicrosoftAdminPortals
Grant
Control access enforcement to block or grant access. Grant access
Authentication strength
For multiple controls Require one of the selected controls
Table 14. Settings - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA

CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Monday, 31 January 2022 16:44:43
Last modified Tuesday, 2 January 2024 10:38:19
Table 15. Basics - CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
Name Value
Users and groups
Include
Include Select users and groups
Directory roles
Exchange Administrator
Security Administrator
Conditional Access Administrator
SharePoint Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Global Administrator
Global Reader
Intune Administrator
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Locations
Include Any location
Client apps
Include Exchange ActiveSync
Browser
Mobile apps and desktop clients
Other clients
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls
Table 16. Settings - CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA

CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

Name Value
Basics
Name CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 10:02:19
Last modified Tuesday, 2 January 2024 10:38:23
Table 17. Basics - CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Name Value
Users and groups
Include
Include Select users and groups
Directory roles
Authentication Administrator
Billing Administrator
Conditional Access Administrator
Exchange Administrator
Global Administrator
Global Reader
Helpdesk Administrator
Intune Administrator
Security Administrator
User Administrator
SharePoint Administrator
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Sign-in frequency 12 hours
Table 18. Settings - CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Monday, 31 January 2022 16:44:44
Last modified Tuesday, 2 January 2024 14:10:23
Table 19. Basics - CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Locations
Include Any location
Client apps
Include Browser
Mobile apps and desktop clients
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls
Table 20. Settings - CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA

CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk

Name Value
Basics
Name CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:45:42
Last modified Wednesday, 24 January 2024 08:53:55
Table 21. Basics - CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
User risk
Include High
Sign-in risk
Include High
Grant
Control access enforcement to block or grant access. Block access
Table 22. Settings - CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk

CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices

Name Value
Basics
Name CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 10:06:50
Last modified Wednesday, 3 January 2024 09:54:21
Table 23. Basics - CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Device platform
Include Windows
macOS
Filter for devices
Exclude filtered devices from policy device.deviceOwnership -eq "Company" -or device.isCompliant -eq True
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Sign-in frequency 12 hours
Table 24. Settings - CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices

CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA

Name Value
Basics
Name CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:30:47
Last modified Tuesday, 2 January 2024 10:39:07
Table 25. Basics - CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include Microsoft Intune Enrollment
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls
Session
Sign-in frequency Every time
Table 26. Settings - CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA

CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms

Name Value
Basics
Name CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:32:55
Last modified Tuesday, 2 January 2024 10:39:24
Table 27. Basics - CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Device platform
Include Any device
Exclude Android
iOS
Windows
macOS
Grant
Control access enforcement to block or grant access. Block access
Table 28. Settings - CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms

CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration

Name Value
Basics
Name CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
Profile type Conditional Access
Enable policy On
Created Wednesday, 3 January 2024 08:08:24
Table 29. Basics - CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration - Exclude
Cloud apps or actions
Cloud apps
Include None
Grant
Control access enforcement to block or grant access. Grant access
Require device to be marked as compliant Enabled
Require Microsoft Entra hybrid joined device Enabled
For multiple controls Require one of the selected controls
Table 30. Settings - CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration

CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ

Name Value
Basics
Name CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:27:49
Last modified Wednesday, 3 January 2024 09:52:28
Table 31. Basics - CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Exclude Microsoft Intune Enrollment
Conditions
Device platform
Include Windows
Grant
Control access enforcement to block or grant access. Grant access
Require device to be marked as compliant Enabled
Require Microsoft Entra hybrid joined device Enabled
For multiple controls Require one of the selected controls
Table 32. Settings - CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ

CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:23:41
Last modified Tuesday, 2 January 2024 10:52:19
Table 33. Basics - CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
Name Value
Users and groups
Include
Include Select users and groups
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls
Table 34. Settings - CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA

CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess

Name Value
Basics
Name CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:37:47
Last modified Wednesday, 27 March 2024 15:06:48
Table 35. Basics - CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
Name Value
Users and groups
Include
Include Select users and groups
Exclude
Users and groups CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Exclude My Apps
Office365
Grant
Control access enforcement to block or grant access. Block access
Table 36. Settings - CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess

CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

Name Value
Basics
Name CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:55:02
Last modified Tuesday, 2 January 2024 10:39:39
Table 37. Basics - CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Name Value
Users and groups
Include
Include Select users and groups
Exclude
Users and groups CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Sign-in frequency 12 hours
Table 38. Settings - CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

Named Locations

ALLOWED COUNTRIES

Name Value
Basics
Name ALLOWED COUNTRIES
Description
Profile type Named locations
Created Wednesday, 7 September 2022 13:48:18
Last modified Friday, 3 February 2023 08:18:30
Table 39. Basics - ALLOWED COUNTRIES
Name Value
Country lookup method Determine location by IP address (IPv4 and IPv6)
Include unknown countries/regions Disabled
Countries

Table 40. Settings - ALLOWED COUNTRIES
S
Description
No description provided
Readme MIT
15 MiB