Skillplan M365 Checklist
2026-07-20 19:31
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 4 of 17
Conditional Access Policies
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Require MFA for all users for all cloud apps as the baseline Conditional Access policy.
Not Fulfilled
Fulfilled
Accepted
Block sign-ins from unsupported device platforms by explicitly allow-listing only the platforms in use.
Not Fulfilled
Fulfilled
Accepted
Block sign-ins from countries where the organization has no presence using Named Locations.
Not Fulfilled
Fulfilled
Accepted
Require compliant or hybrid-joined devices for access to Microsoft 365 services.
Not Fulfilled
Fulfilled
Accepted
Require Intune App Protection Policies for mobile access to Outlook, Teams, and OneDrive.
Not Fulfilled
Fulfilled
Accepted
Disable persistent browser sessions on unmanaged devices via Conditional Access session controls.
Not Fulfilled
Fulfilled
Accepted
Enforce sign-in frequency of at most 24 hours on unmanaged devices.
Not Fulfilled
Fulfilled
Accepted
Run every new policy in Report-only mode for at least 7 days before switching it On.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →