CA-01: Require MFA via Conditional Access Policy

Frequently asked questions about implementing and managing the CA-01 security control in Microsoft 365 and Entra ID.

Q
What is CA-01 (Require MFA via Conditional Access Policy)?
A

CA-01 is a security control that conditional access policies provide granular mfa enforcement with proper exclusions. unlike security defaults, ca policies allow you to exclude emergency access accounts while still protecting all users. It requires that at least one conditional access policy requires mfa for all users and policy applies to all cloud applications, emergency access accounts are excluded, policy state is enabled (not report-only).

Related controls:CA-01
Q
Why is Require MFA via Conditional Access Policy important for Microsoft 365 security?
A

Conditional Access policies provide granular MFA enforcement with proper exclusions. Unlike Security Defaults, CA policies allow you to exclude emergency access accounts while still protecting all users.

Related controls:CA-01
Q
How do I implement CA-01 in my tenant?
A

TrueConfig provides one-click remediation for CA-01. Creates a Conditional Access policy requiring MFA for all users

Related controls:CA-01
Q
What license do I need for CA-01?
A

This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.

Related controls:CA-01
Q
Which security baseline includes CA-01?
A

CA-01 is included in the TrueConfig Recommended Secure baseline (Level 1). This is the foundation level suitable for most organizations.

Related controls:CA-01
Q
Why is CA-01 marked as critical severity?
A

CA-01 is rated critical because failure to implement this control significantly increases the risk of security incidents. Conditional Access policies provide granular MFA enforcement with proper exclusions. Unlike Security Defaults, CA policies allow you to exclude emergency access accounts while still protecting all users.

Related controls:CA-01

6

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial