2024-04-10 07:52:29 +02:00
2024-04-09 14:53:44 +02:00
2024-04-10 07:52:29 +02:00

Conditional Access Baseline

This conditional access baseline is based on the Microsoft Conditional Access Baseline by Claus Jespersen. This one is slightly minimized and less dificult to understand but still protects almost everything you could wish for. Use this baseline to start off with and expend where needed.

Resources

➡ Microsoft Learn: https://learn.microsoft.com/en-us/azure/architecture/guide/security/conditional-access-framework

➡ Framework documentation by Claus Jespersen: https://github.com/microsoft/ConditionalAccessforZeroTrustResources/blob/main/ConditionalAccessGovernanceAndPrinciplesforZeroTrust%20October%202023.pdf

➡ Framework resources: https://github.com/microsoft/ConditionalAccessforZeroTrustResources

Table of Contents

Conditional access

Conditional access policies

CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:47:07
Last modified Wednesday, 27 March 2024 14:41:39
Name Value
Users and groups
Include
Include All users
Exclude
Directory roles Directory Synchronization Accounts
Users and groups
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA000-Global-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls

CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist

Name Value
Basics
Name CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 08:02:06
Last modified Tuesday, 2 January 2024 10:38:04
Table 3. Basics - CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA001-Global-AttackSurfaceReduction-AnyApp-AnyPlatform-BLOCK-CountryWhitelist - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Locations
Include Any location
Exclude ALLOWED COUNTRIES
Grant
Control access enforcement to block or grant access. Block access

CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication

Name Value
Basics
Name CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:08:14
Last modified Tuesday, 2 January 2024 10:38:10
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA002-Global-IdentityProtection-AnyApp-AnyPlatform-Block-LegacyAuthentication - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Client apps
Include Exchange ActiveSync
Other clients
Grant
Control access enforcement to block or grant access. Block access

CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA

Name Value
Basics
Name CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Wednesday, 3 January 2024 07:52:15
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA003-Global-BaseProtection-RegisterOrJoin-AnyPlatform-MFA - Exclude
Cloud apps or actions
User actions
Select the action this policy will apply to Register or join devices
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls

CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows

Name Value
Basics
Name CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows
Profile type Conditional Access
Enable policy On
Created Wednesday, 27 March 2024 14:28:00
Last modified Monday, 8 April 2024 12:38:51
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA004-Global-IdentityProtection-AnyApp-AnyPlatform-AuthenticationFlows - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Block access

CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload

Name Value
Basics
Name CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload
Profile type Conditional Access
Enable policy On
Created Wednesday, 27 March 2024 14:40:41
Last modified Monday, 8 April 2024 12:38:39
Name Value
Users and groups
Include
Include All users
Exclude
Users and groups CA005-Global-DataProtection-Office365-AnyPlatform-Unmanaged-AppEnforcedRestrictions-BlockDownload - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include Office 365 Exchange Online
Office 365 SharePoint Online
Conditions
Client apps
Include Browser
Filter for devices
Exclude filtered devices from policy device.isCompliant -eq True
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Use app enforced restrictions Enabled

CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA

Name Value
Basics
Name CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Friday, 22 December 2023 10:12:23
Last modified Wednesday, 3 January 2024 09:43:35
Name Value
Users and groups
Include
Include Select users and groups
Directory roles
Global Administrator
Security Administrator
SharePoint Administrator
Exchange Administrator
Conditional Access Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Application Administrator
Cloud Application Administrator
Password Administrator
Privileged Authentication Administrator
Privileged Role Administrator
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include MicrosoftAdminPortals
Grant
Control access enforcement to block or grant access. Grant access
Authentication strength
For multiple controls Require one of the selected controls
Table 14. Settings - CA100-Admins-IdentityProtection-AdminPortals-AnyPlatform-MFA

CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Monday, 31 January 2022 16:44:43
Last modified Tuesday, 2 January 2024 10:38:19
Name Value
Users and groups
Include
Include Select users and groups
Directory roles
Exchange Administrator
Security Administrator
Conditional Access Administrator
SharePoint Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Global Administrator
Global Reader
Intune Administrator
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA101-Admins-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Locations
Include Any location
Client apps
Include Exchange ActiveSync
Browser
Mobile apps and desktop clients
Other clients
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls

CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

Name Value
Basics
Name CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 10:02:19
Last modified Tuesday, 2 January 2024 10:38:23
Name Value
Users and groups
Include
Include Select users and groups
Directory roles
Authentication Administrator
Billing Administrator
Conditional Access Administrator
Exchange Administrator
Global Administrator
Global Reader
Helpdesk Administrator
Intune Administrator
Security Administrator
User Administrator
SharePoint Administrator
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA102-Admins-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Sign-in frequency 12 hours

CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Monday, 31 January 2022 16:44:44
Last modified Tuesday, 2 January 2024 14:10:23
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA200-Internals-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Locations
Include Any location
Client apps
Include Browser
Mobile apps and desktop clients
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls

CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk

Name Value
Basics
Name CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:45:42
Last modified Wednesday, 24 January 2024 08:53:55
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA201-Internals-IdentityProtection-AnyApp-AnyPlatform-BLOCK-HighRisk - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
User risk
Include High
Sign-in risk
Include High
Grant
Control access enforcement to block or grant access. Block access

CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices

Name Value
Basics
Name CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 10:06:50
Last modified Wednesday, 3 January 2024 09:54:21
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA202-Internals-IdentityProtection-AllApps-WindowsMacOS-SigninFrequency-UnmanagedDevices - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Device platform
Include Windows
macOS
Filter for devices
Exclude filtered devices from policy device.deviceOwnership -eq "Company" -or device.isCompliant -eq True
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Sign-in frequency 12 hours

CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA

Name Value
Basics
Name CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:30:47
Last modified Tuesday, 2 January 2024 10:39:07
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA203-Internals-AppProtection-MicrosoftIntuneEnrollment-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include Microsoft Intune Enrollment
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls
Session
Sign-in frequency Every time

CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms

Name Value
Basics
Name CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:32:55
Last modified Tuesday, 2 January 2024 10:39:24
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Conditions
Device platform
Include Any device
Exclude Android
iOS
Windows
macOS
Grant
Control access enforcement to block or grant access. Block access

CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration

Name Value
Basics
Name CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration
Profile type Conditional Access
Enable policy On
Created Wednesday, 3 January 2024 08:08:24
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA205-Internals-IdentityProtection-AllApps-AnyPlatform-CombinedRegistration - Exclude
Cloud apps or actions
Cloud apps
Include None
Grant
Control access enforcement to block or grant access. Grant access
Require device to be marked as compliant Enabled
Require Microsoft Entra hybrid joined device Enabled
For multiple controls Require one of the selected controls

CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ

Name Value
Basics
Name CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:27:49
Last modified Wednesday, 3 January 2024 09:52:28
Name Value
Users and groups
Include
Include Select users and groups
Users and groups APP_Microsoft365_E5_Dev
Exclude
Users and groups CA206-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Exclude Microsoft Intune Enrollment
Conditions
Device platform
Include Windows
Grant
Control access enforcement to block or grant access. Grant access
Require device to be marked as compliant Enabled
Require Microsoft Entra hybrid joined device Enabled
For multiple controls Require one of the selected controls

CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA

Name Value
Basics
Name CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 07:23:41
Last modified Tuesday, 2 January 2024 10:52:19
Name Value
Users and groups
Include
Include Select users and groups
Exclude
Users and groups CA-BreakGlassAccounts - Exclude
CA400-GuestUsers-IdentityProtection-AnyApp-AnyPlatform-MFA - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
Require multifactor authentication Enabled
For multiple controls Require one of the selected controls

CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess

Name Value
Basics
Name CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:37:47
Last modified Wednesday, 27 March 2024 15:06:48
Name Value
Users and groups
Include
Include Select users and groups
Exclude
Users and groups CA401-GuestUsers-AttackSurfaceReduction-AllApps-AnyPlatform-BlockNonGuestAppAccess - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Exclude My Apps
Office365
Grant
Control access enforcement to block or grant access. Block access

CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency

Name Value
Basics
Name CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency
Profile type Conditional Access
Enable policy On
Created Tuesday, 2 January 2024 09:55:02
Last modified Tuesday, 2 January 2024 10:39:39
Name Value
Users and groups
Include
Include Select users and groups
Exclude
Users and groups CA402-GuestUsers-IdentityProtection-AllApps-AnyPlatform-SigninFrequency - Exclude
CA-BreakGlassAccounts - Exclude
Cloud apps or actions
Cloud apps
Include All cloud apps
Grant
Control access enforcement to block or grant access. Grant access
For multiple controls Require all the selected controls
Session
Sign-in frequency 12 hours

Named Locations

ALLOWED COUNTRIES

Name Value
Basics
Name ALLOWED COUNTRIES
Description
Profile type Named locations
Created Wednesday, 7 September 2022 13:48:18
Last modified Friday, 3 February 2023 08:18:30
Name Value
Country lookup method Determine location by IP address (IPv4 and IPv6)
Include unknown countries/regions Disabled
Countries

S
Description
No description provided
Readme MIT
15 MiB