What it decides

Rule
CA-STATE-001
Applies to
entra · conditional-access-policy
Default severity
medium
Basis
convention

On what authority

Microsoft states what the mode does, in the reference page for it: "Report- only mode evaluates policies but doesn't enforce grant controls or session controls. Users aren't prompted for multifactor authentication or blocked by report-only policies." That is their sentence and it is not in dispute. Ours is what follows: a policy that enforces nothing sits in the same list as the policies that do, under the same name it will have when it is switched on, and nothing distinguishes one parked there deliberately from one nobody finished. An organisation reading its own policy list is reading a list of intentions, some of which are in force. This says which. A tenant that reviews its report-only policies deliberately can decline this rule, and the declining is the point of a convention.

What it needs to decide

  • policy_state

Without these facts the rule answers unknown, which is not a pass and is not a failure: it is the rule saying the evidence could not settle the question.

Where the evidence comes from

  • conditional-access: the Conditional Access policies, named locations and Security Defaults state of one tenant · provider live-validated, slice not live-validated

What a pass does not establish

A POLICY THAT IS NOT REPORT-ONLY MAY STILL ENFORCE NOTHING. `disabled` is a separate state and this rule does not read it. A policy that is enabled may exclude every user it would otherwise apply to, apply to no application, or require a control that every sign-in already satisfies. This reads the state and nothing else, and a pass says only that the state is not the one Microsoft documents as not enforcing.

  • REPORT-ONLY DOES NOT COVER EVERYTHING, and where it does not, this finding is describing a mode the policy could not have been tested in. Microsoft records that policies scoped to User Actions cannot be evaluated in report-only mode.
  • A report-only policy is not inert on every device. Microsoft warns that one requiring a compliant device can prompt for a device certificate on macOS, iOS and Android during evaluation, so users can be interrupted by a policy that enforces nothing.
  • This rule reads one policy. Whether a tenant is protected is a question about every policy that applies to a sign-in together, and no rule here answers it.

Source

The rule as the Engine holds it, at the revision this page was generated from: 1.0.0b8@2d4f5db76f21.

Generated from capability-manifest/1.0.0 at1.0.0b8@2d4f5db76f21, contract1.0.0b8. Every fact on this page is the Engine's; this site publishes it and does not maintain it.