EIDCA-001: Full CA Policy Inventory

Platform
Entra ID / M365
Category
Entra ID Conditional Access
Severity
Info
Zero Trust pillar
Identity (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

A complete inventory of all Conditional Access policies with their settings should be maintained. This provides visibility into the security posture and enables gap analysis, change tracking, and compliance auditing across the tenant.

Recommended value

All Conditional Access policies documented with state, conditions, grant controls, and session controls

Remediation

Navigate to the Entra admin center Conditional Access blade and export all policies. Review each policy for correct naming conventions, descriptions, and appropriate state (enabled, disabled, or report-only). Maintain a versioned record of all policy configurations for audit purposes.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDCA-001
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

CIS M365 Benchmark
5.2.1