The Zero Trust Starter Kit: 20 Baseline CA Policies
A practical, no-nonsense blueprint for implementing Zero Trust within Microsoft 365. Translate theory into the exact Conditional Access configurations you need without crippling employee productivity.
About This Blueprint
While many vendors treat Zero Trust as abstract theory, this guide translates architecture into the exact 20 Conditional Access (CA) configurations you need to protect Identity, Devices, and Data—maximizing ROI on existing M365 licenses with zero downtime.
The Expected Outcome
By implementing these 20 baseline policies, your organization shifts from a fragile "castle-and-moat" posture to a resilient "Assume Breach" foundation—shutting down common attack vectors and drastically reducing blast radius while maintaining employee trust.
⚠️ The Golden Rule of Deployment
Never deploy these policies in "On" mode immediately. Always deploy in Report-Only mode first for at least 14 days to review Entra ID sign-in logs and surface potential workflow impacts. Secure the business, but never break the business.
The 60-Day Frictionless Deployment Roadmap
Rolling out 20 policies simultaneously causes helpdesk overload. Follow our 4-sprint phased deployment plan to telemetry-test each layer before enforcement.
The Silent Shield
Action: Deploy Phase 1 (Blocks) in Report-Only for 3 days, then switch to ON. Deploy Phase 2 (Identity) in Report-Only.
Goal: Stop automated bot attacks immediately with zero end-user friction.
Identity Enforcement
Action: Switch Phase 2 (Identity) to ON. Deploy Phase 3 (Device Health) in Report-Only mode.
Goal: Secure password vulnerabilities and launch the "Security for Humans" campaign.
The Zero Trust Perimeter
Action: Switch Phase 3 (Device Health) to ON. Deploy Phase 4 (Session/Data) in Report-Only mode.
Goal: Enforce that corporate data can only live on healthy, approved devices.
Advanced Containment
Action: Switch Phase 4 (Session/Data) to ON.
Goal: Lock down session hijacking and set boundaries for Shadow AI tools.
The 20 Baseline Conditional Access Policies
Phase 1: Closing the Front Door (Block Policies)
6 PoliciesShut down outdated, unmanaged, or high-risk entry points to stop automated attacks immediately.
Block Legacy Authentication
Blocks authentication protocols that don't support modern MFA (IMAP, POP3, SMTP, basic auth).
Legacy protocols bypass modern security controls. Attackers use compromised passwords against IMAP/POP3 to skip MFA entirely.
Block High-Risk Sign-ins
Integrates with Entra ID Protection to automatically block logins flagged as highly suspicious (anonymous IPs, impossible travel).
Stops automated credential-stuffing attacks and botnets in real time before initial foothold.
Block Access from High-Risk Countries
Uses geofencing to deny authentication originating from regions where your company does no legitimate business.
Drastically shrinks your global attack surface right at the perimeter.
Block Unsupported Device Platforms
Prevents sign-ins from unmanaged or obsolete OS versions (Linux, ChromeOS, old Windows/Android).
Closes gaps that standard compliance policies miss. If your company uses Windows/macOS/iOS/Android, block unapproved OS attempts.
Block Device Code Flow
Disables OAuth device code authentication designed for devices without a web browser (smart TVs).
Prevents device code phishing attacks that trick users into authenticating attacker sessions.
Block Authentication Transfer
Blocks QR-code-based authentication transfer mechanisms between devices.
Prevents "quishing" (QR phishing) where users scan codes handing over active authenticated sessions to attackers.
Phase 2: Identity & Authentication Protection
6 PoliciesEnforce strict verification for all users, requiring maximum security for administrative privileges.
Require Phishing-Resistant MFA for Admins
Requires admin accounts to authenticate strictly using FIDO2 keys, passkeys, or Windows Hello for Business.
Standard push notifications can be phished via AiTM proxies. Phishing-resistant credentials are domain-bound.
Require Phishing-Resistant MFA for Break-Glass Accounts
Dedicated policy forcing emergency accounts to use hardware FIDO2 keys.
Ensures emergency admin accounts remain protected even if standard policies fail.
Require MFA for Azure & Admin Portals
Mandatory MFA prompt whenever accessing administrative interfaces (Azure Portal, M365 Admin Center).
Locks down the core control plane of your cloud infrastructure.
Require Strong MFA for All Users
Requires modern MFA for every user, explicitly excluding weak methods like SMS and voice calls.
SMS can be SIM-swapped or intercepted. Closing legacy MFA options secures all user endpoints.
Require MFA & Password Reset for Risky Users
Automatically flags accounts with dark-web leaked credentials, requiring MFA + mandatory password reset.
Instantly neutralizes compromised credential leaks.
Require TAP for Security Info & Device Registration
Forces Temporary Access Pass (TAP) or fresh MFA when registering new auth methods or Intune devices.
Prevents an attacker with temporary password access from registering rogue devices.
Phase 3: Device Health & Access Control
3 PoliciesEnsure that devices attempting to access corporate data meet strict security standards.
Require Compliant Device (Desktops & Laptops)
Blocks M365 access from computers not enrolled in Intune and marked compliant (or Entra-joined).
Primary security perimeter gate. Personal devices cannot touch company data unless fully managed.
Require App Protection & Approved Apps (Mobile BYOD)
Forces mobile access exclusively through approved apps protected by Intune App Protection Policies (MAM).
Protects corporate data on personal mobile devices without full device enrollment or touching personal photos.
Block Mobile Browser Access
Denies mobile web browsers (Safari, Chrome) from accessing M365 cloud apps.
Closes BYOD loopholes, preventing users from downloading corporate files to unmanaged phone storage.
Phase 4: Session Controls & Data Protection
5 PoliciesLimit the lifespan and usability of authenticated sessions to minimize data exfiltration and AI risk.
Windows Token Protection
Cryptographically binds authentication tokens to the specific Windows device that requested them.
Stops token theft attacks. Stolen memory tokens become instantly useless on any other machine.
Sign-In Frequency & Session Lifetime Limits
Sets time limits on active user sessions before re-authentication is required.
Limits the blast radius of a stolen session token.
Block Persistent Browser Sessions
Disables persistent browser sign-in states across session closes.
Stops subsequent users on shared or public computers from opening employee sessions.
Block Downloads via Conditional Access App Control
Routes browser sessions through Defender for Cloud Apps to allow web viewing while blocking local file downloads.
Enables safe web document viewing without saving corporate files to unmanaged hard drives.
Block Unsanctioned Generative AI & Web Leaks
Integrates CA with Defender for Cloud Apps to block navigation to consumer AI tools and restrict copy-pasting corporate text into external forms.
Prevents employees from inadvertently pasting proprietary code, PII, or strategy into public AI models.
Security for Humans: Change Management Guidelines
User AdoptionExplain the "Why"
Don't just send an IT memo dictating rules. Host a brief company town hall framing changes around protecting employee hard work and personal data.
Ditch 40-Page Manuals
Provide 1-page visual cheat sheets for setting up Authenticator or enrolling a new device.
30-Day Nudge Campaign
Drip out weekly security tips in Slack/Teams to slowly build a security-first culture without overwhelming staff.
Safe Space Feedback Loop
In Report-Only mode, proactively reach out to users who trigger a block so their setup is fixed before enforcement.
Continuous Protection: Optimizing & Tuning Your Policies
OptimizationMonitor the Telemetry
Conditional Access is only as good as the data you feed it. Regularly review Entra ID Sign-in logs and Azure Monitor workbooks to spot trends and false positives.
Refine Exclusions Carefully
Always scope exclusions as tightly as possible (by specific IP or dedicated service account) rather than excluding entire groups.
Audit Break-Glass Accounts
Exclude emergency admin accounts from standard CA policies, but set up Azure Monitor alerts to notify leadership immediately if used.
Quarterly Strategy Syncs
Schedule a dedicated review every 90 days to review adoption metrics, blocked access attempts, and new AI tools in the workplace.
Need Help Turning This On?
Deploying these 20 policies is the foundation of a secure, resilient business. Let's talk about how to implement them with zero workflow disruption.
Book a 15-Minute Strategy Call →