Ensure a Token Protection Conditional Access policy is considered
Description
This recommendation ensures that issued tokens are only issued to the intended device.
Rationale
When properly configured, conditional access can aid in preventing attacks involving token theft, via hijacking or reply, as part of the attack flow. Although currently considered a rare event, the impact from token impersonation can be severe.
Impact
A Microsoft Entra ID P1 or P2 license is required.
Start with a Conditional Access policy in "Report Only" mode prior to enforcing for all users.
Audit Procedure
Using Azure Portal
- Sign in to the Microsoft Entra admin center as at least a
Conditional Access Administrator. - Browse to
Protection>Conditional Access>Policies. - Review existing policies to ensure that at least one policy contains the following configuration:
- Under
Assignments, reviewUsers or workload identitiesand- Under
Include, ensure the scope of the users or groups is appropriate for your organization. - Under
Exclude, ensure only necessary users and groups (your organization's emergency access or break-glass accounts) are excepted.
- Under
- Under
Target resources>Resources>Include>Select resources: Ensure that bothOffice 365 Exchange OnlineandOffice 365 SharePoint Onlineare selected. - Under
Conditions>Device Platforms: EnsureConfigureis set toYesandIncludeindicatesWindowsplatforms. - Under
Conditions>Client Apps: EnsureConfigureis set toYesandMobile Apps and Desktop Clientsis selected under Modern Authentication Clients. - Under
Access controls>Session, ensure thatRequire token protection for sign-in sessionsis selected.
Expected Result
At least one Conditional Access policy should exist with Token Protection configured, targeting Office 365 Exchange Online and SharePoint Online on Windows platforms with mobile apps and desktop clients.
Remediation
Remediate from Azure Portal
- Sign in to the Microsoft Entra admin center as at least a
Conditional Access Administrator. - Browse to
Protection>Conditional Access>Policies. - Select
New policy. - Give your policy a name.
- Under
Assignments, selectUsers or workload identities.- Under
Include, select the users or groups to apply this policy. - Under
Exclude, select Users and groups and choose your organization's emergency access or break-glass accounts (if applicable).
- Under
- Under
Target resources>Resources>Include>Select resources- Under
Select, select the following applications:- Office 365 Exchange Online
- Office 365 SharePoint Online
- Choose
Select.
- Under
- Under
Conditions:- Under
Device platforms- Set
Configureto Yes. Include>Select device platforms>Windows.- Select
Done.
- Set
- Under
Client apps:- Set
Configureto Yes. - Under Modern authentication clients, only select
Mobile apps and desktop clients. - Select
Done.
- Set
- Under
- Under
Access controls>Session, selectRequire token protection for sign-in sessionsand selectSelect. - Confirm your settings and set Enable policy to
On. - Select
Createto enable your policy.
Default Value
A Token Protection Conditional Access policy does not exist by default.
References
- https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-token-protection
- https://www.microsoft.com/en-gb/security/business/microsoft-entra-pricing
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 6.3 Require MFA for Externally-Exposed Applications | x | x | |
| v8 | 6.4 Require MFA for Remote Network Access | x | x | x |
Profile
Level 2 | Manual