👥CA200: Internals – IdentityProtection – AnyApp – AnyPlatform – MFA
Requires multi-factor authentication (MFA) for all internal users accessing any Microsoft 365 or cloud app.
Why this matters: Provides an essential security baseline by ensuring all employees use MFA, greatly reducing the risk of account compromise through stolen or weak passwords.
🚫CA201: Internals – IdentityProtection – AnyApp – AnyPlatform – BLOCK – HighRisk
Blocks internal users who are flagged as “high risk” from signing into any cloud application.
Why this matters: Automatically prevents compromised accounts from accessing your environment until their risk status is remediated, minimizing potential breach impact.
⏱️CA202: Internals – IdentityProtection – AllApps – Windows/MacOS – Sign-in Frequency – UnmanagedDevices
Requires internal users on unmanaged Windows or macOS devices to re-authenticate periodically (for example, every 12 hours).
Why this matters: Frequent sign-in validation helps ensure unmanaged or personal devices cannot maintain long-term access without verification, lowering exposure to hijacked sessions.
📲CA203: Internals – AppProtection – MicrosoftIntuneEnrollment – AnyPlatform – MFA
Requires MFA when users enroll their devices into Microsoft Intune or other management platforms.
Why this matters: Protects the enrollment process to ensure only legitimate, authenticated users can add devices to your organisation’s managed fleet.
🚫CA204: Internals – AttackSurfaceReduction – AllApps – AnyPlatform – BLOCK – UnknownPlatforms
Blocks access from unrecognised or unsupported device platforms.
Why this matters: Prevents risky or obsolete systems (for example, Linux, old OS versions, or jailbroken devices) from connecting, reducing the attack surface.
🪟CA205: Internals – BaseProtection – AnyApp – Windows – Compliant or AAD Joined
Allows access to cloud apps only from Windows devices that are compliant or Azure AD joined.
Why this matters: Enforces the use of trusted, managed devices that meet corporate compliance standards, strengthening endpoint security posture.
🌐CA206: Internals – IdentityProtection – AllApps – AnyPlatform – PersistentBrowser
Disables persistent browser sessions for internal users on unmanaged devices.
Why this matters: Stops users from remaining signed in indefinitely on shared or personal devices, reducing risks from unattended or stolen hardware.
🚫CA207: Internals – AttackSurfaceReduction – SelectedApps – AnyPlatform – BLOCK
Blocks access to selected high-risk or legacy applications for internal users.
Why this matters: Restricts use of applications known to present security or compliance risks, helping prevent accidental data leakage or shadow IT usage.
🍎CA208: Internals – DeviceCompliance – macOS – RequireCompliantDevice
Ensures macOS devices used by internal users meet Intune compliance policies before accessing cloud applications.
Why this matters: Applies the same compliance rigor to Apple macOS endpoints as Windows, maintaining consistency across your organisation’s device ecosystem.
🔄CA209: Internals – IdentityProtection – AllApps – AnyPlatform – ContinuousAccessEvaluation (CAE)
Enables Continuous Access Evaluation for internal users to re-evaluate session access in real time.
Why this matters: Provides instant reaction to risky events such as password changes, account disablement, or location anomalies—significantly enhancing your zero-trust posture.