Forum Discussion
Jason Benway
Jul 09, 2019Iron Contributor
deplicate conditional access baseline policies
I want to test the End user protection CA policy but I don't want to enable it for all users yet. Is it possible to recreate that baseline but allowing me to limit what users/groups it applies to? I...
- Jul 15, 2019
Yup, you need AAD P2/EMS E5.
VasilMichev
Jul 09, 2019MVP
It's possible. The whole idea behind the baseline policies is to offer a pre-configured policy with relaxed license requirements. If you already have AAD/EMS licenses in your tenant you can create similar policies yourself, with better customizability. In particular, the "user risk" condition can be found under the Conditions group -> Sign-in risk.
Jason Benway
Jul 15, 2019Iron Contributor
VasilMichevMy conditions options are only
device platform
locations
client apps
device state
I have a E5 with EMS E3. I think that includes AAD P1
Is EMS E5 or AAD P2 required to use the sign-in risk?
thanks,jb
- VasilMichevJul 15, 2019MVP
Yup, you need AAD P2/EMS E5.