What it decides
- Rule
CA-STATE-001- Applies to
entra·conditional-access-policy- Default severity
- medium
- Basis
- convention
On what authority
Microsoft states what the mode does, in the reference page for it: "Report- only mode evaluates policies but doesn't enforce grant controls or session controls. Users aren't prompted for multifactor authentication or blocked by report-only policies." That is their sentence and it is not in dispute. Ours is what follows: a policy that enforces nothing sits in the same list as the policies that do, under the same name it will have when it is switched on, and nothing distinguishes one parked there deliberately from one nobody finished. An organisation reading its own policy list is reading a list of intentions, some of which are in force. This says which. A tenant that reviews its report-only policies deliberately can decline this rule, and the declining is the point of a convention.
What it needs to decide
policy_state
Without these facts the rule answers unknown, which is not a pass and is not a failure: it is the rule saying the evidence could not settle the question.
Where the evidence comes from
conditional-access: the Conditional Access policies, named locations and Security Defaults state of one tenant · provider live-validated, slice not live-validated
What a pass does not establish
A POLICY THAT IS NOT REPORT-ONLY MAY STILL ENFORCE NOTHING. `disabled` is a separate state and this rule does not read it. A policy that is enabled may exclude every user it would otherwise apply to, apply to no application, or require a control that every sign-in already satisfies. This reads the state and nothing else, and a pass says only that the state is not the one Microsoft documents as not enforcing.
- REPORT-ONLY DOES NOT COVER EVERYTHING, and where it does not, this finding is describing a mode the policy could not have been tested in. Microsoft records that policies scoped to User Actions cannot be evaluated in report-only mode.
- A report-only policy is not inert on every device. Microsoft warns that one requiring a compliant device can prompt for a device certificate on macOS, iOS and Android during evaluation, so users can be interrupted by a policy that enforces nothing.
- This rule reads one policy. Whether a tenant is protected is a question about every policy that applies to a sign-in together, and no rule here answers it.
Source
The rule as the Engine holds it, at the revision this page was generated from: 1.0.0b8@2d4f5db76f21.
Generated from capability-manifest/1.0.0 at1.0.0b8@2d4f5db76f21, contract1.0.0b8. Every fact on this page is the Engine's; this site publishes it and does not maintain it.