Skip to main content
Category: Microsoft 365 Administration · View source ↗
Connectors: IT Glue Hudu Role: Security & Compliance Owner Outcome: Risk & Compliance When to use: A scheduled/periodic CA review for a managed tenant (quarterly is typical), “are <client>‘s conditional access policies any good?” / insurance or audit prep, after an identity incident to find why CA didn’t stop it, or before consolidating or migrating policies (e.g., off security defaults — see the security-defaults-vs-ca skill). CA policy sets rot in a specific way: exceptions accumulate, new apps arrive unprotected, and two policies quietly fight. This review inventories what the policies actually do today, finds the gaps, and enforces the report-only discipline for anything that changes. Run it: as an on-demand review across every CA policy in the tenant — you compile the inventory, rank findings, and build remediation tickets, a technician exports policies and runs any changes (not a Flow: no schedule trigger, and changes need a human at the console).

Prompt