Conditional access policies for app protection policies Flashcards
(5 cards)
1
Q
What is Conditional Access?
A
A security feature that allows organizations to restrict access to approved client apps.
2
Q
What is the role of Intune app protection policies in Conditional Access?
A
They enforce access restrictions to modern authentication capable client apps.
3
Q
What are the 10 high level steps to create a Conditional Access policy requiring an approved client app or an app protection policy when using an iOS/iPadOS or Android device in Entra ID ?
A
- Entra ID > Conditional Access, Select Create new policy.
- Give your policy a name
- Assignments: select Users or workload identities.
- Under Include, select All users.
- Under Exclude, select Users and groups and exclude at least one account to prevent yourself from being locked out. If you don’t exclude any accounts, you can’t create the policy.
- Target resources > Resources > Include, select All resources
- Under Conditions > Device platforms, set Configure to Yes.
- Under Include, Select device platforms: Choose Android and iOS.
- Under Access controls > Grant, select Grant access.
- Select Require approved client app and Require app protection policy
For multiple controls select Require one of the selected controls
4
Q
What are the 10 high level steps to Require an app protection policy on Windows devices in Entra ID ?
A
- Entra ID > Conditional Access, Select Create new policy.
- Give your policy a name
- Assignments: select Users or workload identities.
- Under Include, select All users.
- Under Exclude, select Users and groups and exclude at least one account to prevent yourself from being locked out. If you don’t exclude any accounts, you can’t create the policy.
- Target resources > Resources > Include, select Office365
- Under Conditions > Device platforms, set Configure to Yes.
- Under Include, Select device platforms: Choose Windows
- Under Access controls > Grant, select Grant access.
- Select Require approved client app and Require device to bbe marked as compliant
For multiple controls select Require one of the selected controls
5
Q
What are the 8 high level steps to create an app protection policy using conditional launch actions in Intune ?
A
- Select Endpoint security, and under Manage, select Conditional access, select Create new policy.
- enter a policy Name
- Assignments: select Users You can use the Include or Exclude options to refine the users and groups for the policy.
- Cloud apps or actions and apply the policy to Cloud apps, Use the Include or Exclude options to select the apps to protect.
- Optionally, select the Network option: use the Include and Exclude options to specify networks your users can or cannot use for access.
- Conditions : select Client apps to apply the policy to apps and browsers then select your client app options.
-
Access controls, select Grant to apply control access enforcement based on a device compliance status
Particular relevance for the control of the use of apps are:
■ Require approved client app You can define a list of approved client apps the user must use in order to be granted access. However, this setting is being phased out.
■ *Require app protection policy *Requires that a user’s app is protected by an app protection policy before access can be granted. - Select and configure the Session option to create session-based restrictions for Office 365, SharePoint Online, and Exchange Online cloud apps.