What the Engine publishes

Generated from the Engine's capability manifest at1.0.0b8@2d4f5db76f21. No value on this panel is maintained by this site.

Answers
the Conditional Access policies, named locations and Security Defaults state of one tenant
Collector
Microsoft Graph · mode ConditionalAccess
Reads
  • GET /v1.0/identity/conditionalAccess/policies
  • GET /v1.0/identity/conditionalAccess/namedLocations
  • GET /v1.0/policies/identitySecurityDefaultsEnforcementPolicy
Least privilege
  • Policy.Read.All
Produces
entra ·conditional-access-policy
Proven against a tenant
provider live-validated, slice not live-validated

Rules that decide from it

  • CA-STATE-001The policy is in report-only mode and enforces nothingconvention

Contracts it produces

Every collection writes evidence and an account of itself. The manifest publishes no narrower per-capability list, so this states what it does establish rather than guessing at more.

Source

The Engine's own definition of this collector, at the revision this page was generated from:1.0.0b8@2d4f5db76f21.

Generated from capability-manifest/1.0.0 at1.0.0b8@2d4f5db76f21, contract1.0.0b8. Every fact on this page is the Engine's; this site publishes it and does not maintain it.