Sheet1

Conditional Access Blueprint
persona #1 persona #2 persona #3 persona #4 persona #5 persona #6 persona #7 persona #8 persona #9 persona #10
!! THIS IS AN EXAMPLE !! All users General users Service Accounts ADM users DEV users ... ... ... ... ...
It is possible for this persona to... Create below CA policies as needed. Then include or exclude personas
❌ Block full access NO NO ? ? ? ? ? ? ? ? CA – All Apps : Full block
✔️ Require MFA YES YES ? ? ? ? ? ? ? ? CA – All Apps : Require MFA
✔️ Require phishing-resistant MFA NO NO ? ? ? ? ? ? ? ? CA – All Apps : Require phishing-resistant MFA
✔️ Require a compliant device YES YES ? ? ? ? ? ? ? ? CA – All Apps : Require compliant device
✔️ Require device state NO YES ? ? ? ? ? ? ? ?
✔️ Require phishing-resistant MFA with Authentication context NO NO ? ? ? ? ? ? ? ? CA – All Apps: Require phishing-resistant MFA with Authentication Context
❌ Block devices without 'Corporate' Intune ownership YES YES ? ? ? ? ? ? ? ? CA – All Apps : Require corporate owned devices
❌ Block other device IDs NO NO ? ? ? ? ? ? ? ? CA – All Apps : Allow deviceID for AD Sync accounts
❌ Block unknow/other Operating Systems YES Block every OS except Windows YES Block every OS except Windows ? ? ? ? ? ? ? ? CA – All Apps : Block unknown Operating Systems
❌ Block based on device Extension Attribute NO YES Device Attribute 'XXX' ? ? ? ? ? ? ? ? CA – All Apps : Block all devices except Extension Attribute ‘MeetingRoomDevices’
❌ Block based on device properties (device name, manufacturer, model, ...) NO ? ? ? ? ? ? ? ? ? CA – All Apps : Only allow manufacturer X
❌ Block Old Operating Systems versions YES Block below version 10.0 ? ? ? ? ? ? ? ? ? CA – All Apps : Block old Windows versions
❌ Block mobile Operating Systems (Android and iOS) NO ? ? ? ? ? ? ? ? ? CA – All Apps: Block Android and iOS
✔️ Require App Protection Policy NO ? ? ? ? ? ? ? ? ? CA – All Apps : Require App Protection Policies (Android + iOS)
❌ Block non-trusted IP (ranges) NO ? ? ? ? ? ? ? ? ? CA – All Apps : Require trusted IP
❌ Block other countries NO ? ? ? ? ? ? ? ? ? CA – All Apps : Allow USA and Europe
❌ Block access to other applications NO ? ? ? ? ? ? ? ? ? CA – O365 : Allow access
✔️ Sign-in Frequency YES ? ? ? ? ? ? ? ? ? CA – All Apps : Sign-in frequency 2 weeks
✔️ Token Protection (preview) YES Scoped on O365 ? ? ? ? ? ? ? ? ? CA – O365 : Require Token Protection
❌ Block access from desktop apps NO ? ? ? ? ? ? ? ? ? CA – O365 : Block desktop app
✔️ Apply Conditional Access App Control NO ? ? ? ? ? ? ? ? ? CA – All Apps : CA App Controls
❌ Block legacy authentication clients YES ? ? ? ? ? ? ? ? ? CA – All Apps : Block legacy authentication
❌ Block 'Device code' authentication flow YES ? ? ? ? ? ? ? ? ? CA – All Apps : Block device code authentication
✔️ Take action on identity risk YES ? ? ? ? ? ? ? ? ? CA – All Apps : Block for All Users when high sign-in risk
✔️ Require additional controls NO ? ? ? ? ? ? ? ? ? CA – All Apps : Require addidional control
✔️ Restrict MFA registration (via TAP, exclude location / device) YES ? ? ? ? ? ? ? ? ? CA – All Apps: Require trusted location on MFA registration
✔️ Require MFA when users join or register YES ? ? ? ? ? ? ? ? ? CA – All Apps : Require MFA on device join
YES : action applicable to persona
NO : action not applicable to persona
? : TBD
Next steps:
Now group these personas in Conditional Access policies based on their common actions. Then, add the personas to the policy. No need to create a seperate policy for each persona.