ssc-spc-ccoe-cei / azure-guardrails-solution-accelerator

This implementation automates reporting to verify compliance with GC Cloud Guardrails. SSC and TBS review the results. Cette mise en œuvre automatise la production de rapports afin de vérifier la conformité aux mesures de sécurité infonuagique du GC. SPC et SCT examinent les résultats.
Other
7 stars 4 forks source link

GR1 | Validation 2| All Cloud User Accounts MFA Conditional Access Policy (M) #133

Open MathesonSho opened 3 months ago

MathesonSho commented 3 months ago

ItemName ENG: “All Cloud User Accounts MFA Conditional Access Policy (M)” ItemName FR: "Tous les comptes d’utilisateurs infonuagiques stratégie d’accès conditionnel AMF (M)"

Description: This is an existing control “Multi-Factor authentication required for all users by Conditional Access Policy” from GR3 in v1.0 Renamed to “All Cloud User Accounts MFA Conditional Access Policy (M)”. The intention is to ensure All User Accounts are adhering to a Conditional Access Policy enforcing MFA to login.

Opportunities to Improve the Existing MFA Conditional Access Policy

# check for a conditional access policy which meets these requirements:
# 1. state =  'enabled'
# 2. includedUsers = 'All'
# 3. includedApplications = 'All'
# 4. grantControls.builtInControls contains 'mfa'
# 5. clientAppTypes contains 'all'
# 6. userRiskLevels = @()
# 7. signInRiskLevels = @()
# 8. platforms = null
# 9. locations = null
# 10. devices = null
# 11. clientApplications = null

Optional Improvement: How often is this CAP applied to end users? Every single time vs per session?