Best (non-MS) resources on Conditional Access as Code
David Caddick
Senior Security Specialist at Microsoft - aka.ms/gsd = Get Security Deployed
Cory Zaner asked: do you know if it (Conditional Access) can be automated?
Well, most things in IT can be automated, and in the Microsoft world this is generally the case with any aspect of Azure - but in the M365 Defender Security space this is generally limited to Operational items - but Conditional Access is one area that can be Automated.
So unlike most of the other Features in M365 Defender, this can be modified by API access - the best set of resources that I know of (in order) would be:
He also points out the others that have done great work in this space:
One important point – don’t get caught up trying to manage GUID’s:
Identity and Security Architect at Insight - implementing cost effective security controls to mitigate risks
2 年And to help make sure that you are fully covered use this https://github.com/AzureAD/AzureADAssessment
Identity and Security Architect at Insight - implementing cost effective security controls to mitigate risks
2 年Here is a great new companion https://danielchronlund.com/2022/04/21/a-powerfull-conditional-access-change-dashboard-for-microsoft-sentinel/
Certified Ethical Hacker
2 年Cory Zaner I owe you for asking this question. And thank you David Caddick for he great information.
Senior Security Specialist at Microsoft - aka.ms/gsd = Get Security Deployed
2 年And just adding here the?#Microsoft?content: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-apis https://github.com/Azure-Samples/azure-ad-conditional-access-apis/tree/main/03-deploy https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/plan-conditional-access https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-cloud-apps https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-policies https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/ https://learn.microsoft.com/en-us/powershell/module/azuread/get-azureadmsconditionalaccesspolicy?view=azureadps-2.0 https://techcommunity.microsoft.com/t5/itops-talk-blog/deep-dive-how-does-conditional-access-block-legacy/ba-p/3265345
Cybersecurity Manager | Veteran | MSIS | Driving Secure Cloud Solutions at Chevron Phillips
2 年Your man! Ton of great content, I will deep dive tomorrow