| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | persona #1 | | persona #2 | | persona #3 | | persona #4 | | persona #5 | | persona #6 | | persona #7 | | persona #8 | | persona #9 | | persona #10 | | | |
| !! THIS IS AN EXAMPLE !! | | | | | | | All users | | General users | | Service Accounts | | ADM users | | DEV users | | ... | | ... | | ... | | ... | | ... | | | |
| | | | | | | | | | | | | | | | | | |
| It is possible for this persona to... | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Create below CA policies as needed. Then include or exclude personas |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| ❌ Block full access | | | | | | | NO | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Full block |
| ✔️ Require MFA | | | | | | | YES | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require MFA |
| ✔️ Require phishing-resistant MFA | | | | | | | NO | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require phishing-resistant MFA |
| ✔️ Require a compliant device | | | | | | | YES | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require compliant device |
| ✔️ Require device state | | | | | | | NO | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | |
| ✔️ Require phishing-resistant MFA with Authentication context | | | | | | | NO | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps: Require phishing-resistant MFA with Authentication Context |
| ❌ Block devices without 'Corporate' Intune ownership | | | | | | | YES | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require corporate owned devices |
| ❌ Block other device IDs | | | | | | | NO | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Allow deviceID for AD Sync accounts |
| ❌ Block unknow/other Operating Systems | | | | | | | YES | Block every OS except Windows | | YES | Block every OS except Windows | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Block unknown Operating Systems |
| ❌ Block based on device Extension Attribute | | | | | | | NO | | | YES | Device Attribute 'XXX' | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Block all devices except Extension Attribute ‘MeetingRoomDevices’ |
| ❌ Block based on device properties (device name, manufacturer, model, ...) | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Only allow manufacturer X |
| ❌ Block Old Operating Systems versions | | | | | | | YES | Block below version 10.0 | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Block old Windows versions |
| ❌ Block mobile Operating Systems (Android and iOS) | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps: Block Android and iOS |
| ✔️ Require App Protection Policy | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require App Protection Policies (Android + iOS) |
| ❌ Block non-trusted IP (ranges) | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require trusted IP |
| ❌ Block other countries | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Allow USA and Europe |
| ❌ Block access to other applications | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – O365 : Allow access |
| ✔️ Sign-in Frequency | | | | | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Sign-in frequency 2 weeks |
| ✔️ Token Protection (preview) | | | | | | | YES | Scoped on O365 | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – O365 : Require Token Protection |
| ❌ Block access from desktop apps | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – O365 : Block desktop app |
| ✔️ Apply Conditional Access App Control | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : CA App Controls |
| ❌ Block legacy authentication clients | | | | | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Block legacy authentication |
| ❌ Block 'Device code' authentication flow | | | | | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Block device code authentication |
| ✔️ Take action on identity risk | | | | | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Block for All Users when high sign-in risk |
| ✔️ Require additional controls | | | | | | | NO | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require addidional control |
| ✔️ Restrict MFA registration (via TAP, exclude location / device) | | | | | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps: Require trusted location on MFA registration |
| ✔️ Require MFA when users join or register | | | | | | | YES | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | ? | | | | CA – All Apps : Require MFA on device join |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| YES : action applicable to persona | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| NO : action not applicable to persona | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| ? : TBD | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| Next steps: | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| Now group these personas in Conditional Access policies based on their common actions. Then, add the personas to the policy. No need to create a seperate policy for each persona. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |