CA016 (Admin Portals) vs CA006 (AZM)

mrjohn44141 80 Reputation points
2023-08-29T08:43:49.3733333+00:00

Hello great people!

So recently we where introduced to a new fantastic CA rule called CA016:
https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/how-to-policy-mfa-admin-portals

This CA rule will cover Microsoft Administration Portals (preview). The previous CA rule that was available was called CA006 and covered Microsoft Azure Management . Reading the documentation available im still not sure about the following:

Will CA006 be the more robust CA rule that covers both Admin Portals and other items (such as CLI, DevOps, Powershell etc) or will the new CA016, currently in preview, be needed to cover the Administration Portals? I do belive that CA006 covers it all, but i just want to make sure as i havent been able to test it - maybe someone of you guys have? Or even get an official statement.

Greatly appreciated.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2023-08-30T06:04:13.5466667+00:00

    @mrjohn44141 Thank you for reaching out to us, As I understand you are looking for differences between these two CA templates Require multifactor authentication for admins accessing Microsoft admin portals (CA016) vs Require MFA for Azure management (CA006).

    A new application group called Microsoft Admin Portals (Preview) in conditional access policy management wizard which protects five Microsoft admin portals:

    • Microsoft 365 Admin Center
    • Exchange admin center
    • Azure portal
    • Microsoft Entra admin center
    • Security and Microsoft Purview compliance portal

    The Microsoft Admin Portals app group applies to interactive sign-ins to the listed admin portals only. Sign-ins to the underlying resources or services like Microsoft Graph or Azure Resource Manager APIs are not covered by this template. Those resources are protected by the Require multi-factor authentication for Azure management template

    Reference:

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-cloud-apps#microsoft-azure-management:~:text=app%20suite.-,Microsoft%20Azure%20Management,-When%20Conditional%20Access

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-cloud-apps#microsoft-azure-management:~:text=Management%20API%20application.-,Microsoft%20Admin%20Portals%20(preview),-When%20a%20Conditional

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.