EIDCA-003: CA Policies in Report-Only Mode
- Platform
- Entra ID / M365
- Category
- Entra ID Conditional Access
- Severity
- Medium
- Zero Trust pillar
- Identity (weight 3)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Conditional Access policies left in report-only mode do not enforce security controls and only log what would have happened. Policies that have completed testing should be switched to the enabled state to actively protect the environment.
Recommended value
No policies in report-only mode unless actively being tested with a defined transition timeline
Remediation
Review all Conditional Access policies currently in report-only mode and evaluate their sign-in log impact data. For policies that have been validated and show acceptable impact, change the state from report-only to enabled. Establish a policy lifecycle process that defines maximum report-only durations before enforcement.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CIS M365 Benchmark
- 5.2.1