microsoft / Application-Insights-Workbooks

Templates for Azure Monitor Workbooks
MIT License
562 stars 462 forks source link

Conditional Access Gap Analysis - Windows Sign In should be removed from App Report #1824

Open JefTek opened 2 years ago

JefTek commented 2 years ago

In reviewing the CA GAP Analysis workbook, in the Unprotected Applications section, the report of Number of Users Signing in to Applications with Conditional Access Policies Not applied, it includes the Windows Sign-In "app"

image

This is the sign in to the Windows device and PRT acquisition process and would not be in scope of CA. This causes lots of "noise" in the report since most users will have this event.

Can we remove the "Windows Sign-In" app from this report?

gardnerjr commented 2 years ago

@sabinasmith It looks like you might be the author of this template?

james-seddon-paymentsense commented 1 year ago

Any update on this? Also facing the same issue, 60% of our logins not covered by MFA are from "Windows Sign In" which isn't covered by conditional access, so it makes zero sense for these to be reported on at all.

c3rberus commented 1 year ago

Agreed, this should not be part of the report.

james-seddon-paymentsense commented 1 year ago

@sabinasmith did you ever look in to this?

Palciny commented 11 months ago

@gardnerjr can you review my changes in #2418 that fix this Issue?

gardnerjr commented 11 months ago

@palciny someone from the Azure AD Workbooks team needs to approve, they're the codeowners of that area.

KeysAU commented 3 weeks ago

Same issue, can this please be fixed. 2022! this bug was logged.