Sheet1

Conditional Access Blueprint
persona #1persona #2persona #3persona #4persona #5persona #6persona #7persona #8persona #9persona #10
!! THIS IS AN EXAMPLE !!All usersGeneral usersService AccountsADM usersDEV users...............
It is possible for this persona to...Create below CA policies as needed. Then include or exclude personas
Block full accessNONO????????CA – All Apps : Full block
✔️ Require MFAYESYES????????CA – All Apps : Require MFA
✔️ Require phishing-resistant MFANONO????????CA – All Apps : Require phishing-resistant MFA
✔️ Require a compliant deviceYESYES????????CA – All Apps : Require compliant device
✔️ Require device stateNOYES????????
✔️ Require phishing-resistant MFA with Authentication contextNONO????????CA – All Apps: Require phishing-resistant MFA with Authentication Context
Block devices without 'Corporate' Intune ownershipYESYES????????CA – All Apps : Require corporate owned devices
Block other device IDsNONO????????CA – All Apps : Allow deviceID for AD Sync accounts
Block unknow/other Operating SystemsYESBlock every OS except WindowsYESBlock every OS except Windows????????CA – All Apps : Block unknown Operating Systems
Block based on device Extension AttributeNOYESDevice Attribute 'XXX'????????CA – All Apps : Block all devices except Extension Attribute ‘MeetingRoomDevices’
Block based on device properties (device name, manufacturer, model, ...)NO?????????CA – All Apps : Only allow manufacturer X
Block Old Operating Systems versionsYESBlock below version 10.0?????????CA – All Apps : Block old Windows versions
Block mobile Operating Systems (Android and iOS)NO?????????CA – All Apps: Block Android and iOS
✔️ Require App Protection PolicyNO?????????CA – All Apps : Require App Protection Policies (Android + iOS)
Block non-trusted IP (ranges)NO?????????CA – All Apps : Require trusted IP
Block other countriesNO?????????CA – All Apps : Allow USA and Europe
Block access to other applicationsNO?????????CA – O365 : Allow access
✔️ Sign-in FrequencyYES?????????CA – All Apps : Sign-in frequency 2 weeks
✔️ Token Protection (preview)YESScoped on O365?????????CA – O365 : Require Token Protection
Block access from desktop appsNO?????????CA – O365 : Block desktop app
✔️ Apply Conditional Access App ControlNO?????????CA – All Apps : CA App Controls
Block legacy authentication clientsYES?????????CA – All Apps : Block legacy authentication
Block 'Device code' authentication flowYES?????????CA – All Apps : Block device code authentication
✔️ Take action on identity riskYES?????????CA – All Apps : Block for All Users when high sign-in risk
✔️ Require additional controlsNO?????????CA – All Apps : Require addidional control
✔️ Restrict MFA registration (via TAP, exclude location / device)YES?????????CA – All Apps: Require trusted location on MFA registration
✔️ Require MFA when users join or registerYES?????????CA – All Apps : Require MFA on device join
YES : action applicable to persona
NO : action not applicable to persona
? : TBD
Next steps:
Now group these personas in Conditional Access policies based on their common actions. Then, add the personas to the policy. No need to create a seperate policy for each persona.