Azure Active Directory Security and Office 365 Interaction Chart

Jim Hill 96 Reputation points
2020-01-02T14:42:38.123+00:00

I am doing my annual security audit (a few days late) and were wondering if anyone has put together a chart showing the interaction between the various elements of Azure Active Directory as it relates to Office 365. There are so many layers when we consider:

  1. Azure conditional access policies,
  2. Exchange mail flow and spam rules,
  3. Windows Defender Advanced Threat Protection (Enterprise E5 users)
  4. Cloud App security policies and notification rules

Not to mention the authentication polices I have in place for Exchange Online, MFA policies, on and on. I have a good handle on how it all works together, but have never put together a chart showing the interaction of the various elements and the order of application. Example, in Exchange online the authentication policy comes first, with MFA, then the conditional access policy. For a CA rule blocking sign on from a restricted region, the flow goes through the authentication policy, then MFA, then to the CA policy. Alerts fire according to the Cloud App Security policy in the first step.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,561 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 95,666 Reputation points MVP
    2020-01-02T17:58:59.443+00:00

    You wont fine any records in the event log about auth policies, so you can ignore that part. Other than that, I'm not entirely sure what exactly you are looking for, as just the transport pipeline can take several pages to describe properly...

    0 comments No comments

  2. Jim Hill 96 Reputation points
    2020-01-02T18:21:14.107+00:00

    I will just put together a brief, written summary and use that in my audit. Thanks for your reply.

    0 comments No comments