Tenant setup 07 β Conditional Access Policies, part 2
π Complete tenant-setup cookbook in one PDF This article is part of the series. Full series + screenshots in one document: download PDF . (PDF is currently in Czech.
This article is part of the series. Full series + screenshots in one document: download PDF. (PDF is currently in Czech.)
In today's article we'll cover more CAP policies that I recommend as a baseline for any Business Premium tenant. CAP is creative β if you need to allow or block something specific, CAP can almost always do it. The next policy is Require MFA for all users. This one can be tricky if your employees aren't the most tech-savvy, but it's enormously important and blocks almost every attack. With more employees, roll it out in waves. From experience, 5 at once is fine, 50 absolutely is not.
First create a security group you'll add users to manually. Yes, it's a chore, but rolling everyone out at once is worse. Create the group in Entra β Identity β Groups. Use your naming convention. Add the first wave of users.
Open CAP β New policy from template β Require multifactor authentication for all users. Open the policy β Users β Select users and groups β Users and groups and pick the security group. Exclude your break-glass. Done.
Last for today: a TAP-required device-join policy. There's no template for this one β create from scratch. Target all users (exclude break-glass). Target resources β User actions β Register or join devices. Grant β Require authentication strength β pick the TAP strength you created earlier. Save in Report-only.