|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
persona #1 |
|
|
persona #2 |
|
|
persona #3 |
|
|
persona #4 |
|
|
persona #5 |
|
|
persona #6 |
|
|
persona #7 |
|
|
persona #8 |
|
|
persona #9 |
|
|
persona #10 |
|
|
|
|
| !! THIS IS AN EXAMPLE !! |
|
|
|
|
|
|
All users |
|
|
General users |
|
|
Service Accounts |
|
|
ADM users |
|
|
DEV users |
|
|
... |
|
|
... |
|
|
... |
|
|
... |
|
|
... |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| It is possible for this persona to... |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Create below CA policies as needed. Then include or exclude
personas |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ❌ Block full access |
|
|
|
|
|
|
NO |
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Full block |
| ✔️ Require MFA |
|
|
|
|
|
|
YES |
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require MFA |
| ✔️ Require phishing-resistant MFA |
|
|
|
|
|
|
NO |
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require phishing-resistant MFA |
| ✔️ Require a compliant device |
|
|
|
|
|
|
YES |
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require compliant device |
| ✔️ Require device state |
|
|
|
|
|
|
NO |
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
|
| ✔️ Require phishing-resistant MFA with Authentication
context |
|
|
|
|
|
|
NO |
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps: Require phishing-resistant MFA with Authentication
Context |
| ❌ Block devices without 'Corporate' Intune
ownership |
|
|
|
|
|
|
YES |
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require corporate owned devices |
| ❌ Block other device IDs |
|
|
|
|
|
|
NO |
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Allow deviceID for AD Sync accounts |
| ❌ Block unknow/other Operating Systems |
|
|
|
|
|
|
YES |
Block every OS except Windows |
|
YES |
Block every OS except Windows |
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Block unknown Operating Systems |
| ❌ Block based on device Extension Attribute |
|
|
|
|
|
|
NO |
|
|
YES |
Device Attribute 'XXX' |
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Block all devices except Extension Attribute
‘MeetingRoomDevices’ |
| ❌ Block based on device properties (device name,
manufacturer, model, ...) |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Only allow manufacturer X |
| ❌ Block Old Operating Systems versions |
|
|
|
|
|
|
YES |
Block below version 10.0 |
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Block old Windows versions |
| ❌ Block mobile Operating Systems (Android and
iOS) |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps: Block Android and iOS |
| ✔️ Require App Protection Policy |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require App Protection Policies (Android + iOS) |
| ❌ Block non-trusted IP (ranges) |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require trusted IP |
| ❌ Block other countries |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Allow USA and Europe |
| ❌ Block access to other applications |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – O365 : Allow access |
| ✔️ Sign-in Frequency |
|
|
|
|
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Sign-in frequency 2 weeks |
| ✔️ Token Protection (preview) |
|
|
|
|
|
|
YES |
Scoped on O365 |
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – O365 : Require Token Protection |
| ❌ Block access from desktop apps |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – O365 : Block desktop app |
| ✔️ Apply Conditional Access App Control |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : CA App Controls |
| ❌ Block legacy authentication clients |
|
|
|
|
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Block legacy authentication |
| ❌ Block 'Device code' authentication flow |
|
|
|
|
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Block device code authentication |
| ✔️ Take action on identity risk |
|
|
|
|
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Block for All Users when high sign-in risk |
| ✔️ Require additional controls |
|
|
|
|
|
|
NO |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require addidional control |
| ✔️ Restrict MFA registration (via TAP, exclude location /
device) |
|
|
|
|
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps: Require trusted location on MFA registration |
| ✔️ Require MFA when users join or register |
|
|
|
|
|
|
YES |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
? |
|
|
|
CA – All Apps : Require MFA on device join |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| YES : action applicable to persona |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| NO : action not applicable to persona |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ? : TBD |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Next steps: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Now group these personas in Conditional Access policies based on
their common actions. Then, add the personas to the policy. No need to
create a seperate policy for each persona. |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|