Remediation
From Azure Portalβ
- From Azure Home select the Portal Menu in the top left, and select
Microsoft Entra ID
. - Select
Security
- Select
Conditional Access
. - Select
Policies
. - Click
+ New policy
. - Enter a name for the policy.
- Click the blue text under
Users
. - Under
Include
, selectAll users
. - Under
Exclude
, checkUsers and groups
. - Select users this policy should not apply to and click
Select
. - Click the blue text under
Target resources
. - Select
All cloud apps
. - Click the blue text under
Conditions
. - Select
Sign-in risk
. - Update the
Configure
toggle toYes
. - Check the sign-in risk level this policy should apply to, e.g.
High
andMedium
. - Select
Done
. - Click the blue text under
Grant
and checkRequire multifactor authentication
then click theSelect
button. - Click the blue text under
Session
then checkSign-in frequency
and selectEvery time
and click theSelect
button. - Set
Enable policy
toReport-only
. - Click
Create
.
After testing the policy in report-only mode, update the Enable policy
setting from Report-only
to On
.