SOLVED

9 top recommended conditional access policies to secure your Microsoft 365 environment

Brass Contributor

1. Block login except from certain countries
2. Block unused device operating systems
3. Require compliant devices
4. Require Hybrid Azure AD joined device
5. Require an app protection policy
6. Block high-user risk
7. Block high sign-in risk
8. Require MFA
9. Block basic/legacy authentication

 

To learn how to set them up go to 9 Conditional Access Policies You'll Kick Yourself for Not Setting Up 

3 Replies
best response confirmed by John Gruber (Brass Contributor)
Solution
For 6 and 7 I would rather choose self-remediation of the high risk with password change and MFA ;)

@John Gruber - why require Hybrid Joined devices?  This flies in the face of current Microsoft preference to move customers to a cloud-only solution, meaning Azure joined only.

@RonS_ except "hybrid" is an official end state. 

1 best response

Accepted Solutions
best response confirmed by John Gruber (Brass Contributor)
Solution
For 6 and 7 I would rather choose self-remediation of the high risk with password change and MFA ;)

View solution in original post