Sheet1

Conditional Access Blueprint
persona #1persona #2persona #3persona #4persona #5persona #6persona #7persona #8persona #9persona #10
!! THIS IS AN EXAMPLE !!All usersGeneral usersService AccountsADM usersDEV users...............
It is possible for this persona to...Create below CA policies as needed. Then include or exclude personas
❌ Block full accessNONO????????CA – All Apps : Full block
✔️ Require MFAYESYES????????CA – All Apps : Require MFA
✔️ Require phishing-resistant MFANONO????????CA – All Apps : Require phishing-resistant MFA
✔️ Require a compliant deviceYESYES????????CA – All Apps : Require compliant device
✔️ Require device stateNOYES????????
✔️ Require phishing-resistant MFA with Authentication contextNONO????????CA – All Apps: Require phishing-resistant MFA with Authentication Context
❌ Block devices without 'Corporate' Intune ownershipYESYES????????CA – All Apps : Require corporate owned devices
❌ Block other device IDsNONO????????CA – All Apps : Allow deviceID for AD Sync accounts
❌ Block unknow/other Operating SystemsYESBlock every OS except WindowsYESBlock every OS except Windows????????CA – All Apps : Block unknown Operating Systems
❌ Block based on device Extension AttributeNOYESDevice Attribute 'XXX'????????CA – All Apps : Block all devices except Extension Attribute ‘MeetingRoomDevices’
❌ Block based on device properties (device name, manufacturer, model, ...)NO?????????CA – All Apps : Only allow manufacturer X
❌ Block Old Operating Systems versionsYESBlock below version 10.0?????????CA – All Apps : Block old Windows versions
❌ Block mobile Operating Systems (Android and iOS)NO?????????CA – All Apps: Block Android and iOS
✔️ Require App Protection PolicyNO?????????CA – All Apps : Require App Protection Policies (Android + iOS)
❌ Block non-trusted IP (ranges)NO?????????CA – All Apps : Require trusted IP
❌ Block other countriesNO?????????CA – All Apps : Allow USA and Europe
❌ Block access to other applicationsNO?????????CA – O365 : Allow access
✔️ Sign-in FrequencyYES?????????CA – All Apps : Sign-in frequency 2 weeks
✔️ Token Protection (preview)YESScoped on O365?????????CA – O365 : Require Token Protection
❌ Block access from desktop appsNO?????????CA – O365 : Block desktop app
✔️ Apply Conditional Access App ControlNO?????????CA – All Apps : CA App Controls
❌ Block legacy authentication clientsYES?????????CA – All Apps : Block legacy authentication
❌ Block 'Device code' authentication flowYES?????????CA – All Apps : Block device code authentication
✔️ Take action on identity riskYES?????????CA – All Apps : Block for All Users when high sign-in risk
✔️ Require additional controlsNO?????????CA – All Apps : Require addidional control
✔️ Restrict MFA registration (via TAP, exclude location / device)YES?????????CA – All Apps: Require trusted location on MFA registration
✔️ Require MFA when users join or registerYES?????????CA – All Apps : Require MFA on device join
YES : action applicable to persona
NO : action not applicable to persona
? : TBD
Next steps:
Now group these personas in Conditional Access policies based on their common actions. Then, add the personas to the policy. No need to create a seperate policy for each persona.