CA-09: Zero Trust Network Access

Frequently asked questions about implementing and managing the CA-09 security control in Microsoft 365 and Entra ID.

Q
What is CA-09 (Zero Trust Network Access)?
A

CA-09 is a security control that full zero trust: never trust, always verify. every access request is validated against device health, user risk, and location. this ensures compromised devices and credentials cannot access resources. It requires that all cloud app access requires a compliant device and named locations are configured for corporate networks, location-based blocking policies are enforced, risk-based sign-in policies are active.

Related controls:CA-09
Q
Why is Zero Trust Network Access important for Microsoft 365 security?
A

Full Zero Trust: never trust, always verify. Every access request is validated against device health, user risk, and location. This ensures compromised devices and credentials cannot access resources.

Related controls:CA-09
Q
How do I implement CA-09 in my tenant?
A

TrueConfig provides one-click remediation for CA-09. Creates a CA policy requiring device compliance for all cloud apps. PREREQUISITE: Intune device compliance policies must be configured.

Related controls:CA-09
Q
What license do I need for CA-09?
A

This control requires Azure AD Premium P2 (included in Microsoft 365 E5) or standalone P2.

Related controls:CA-09
Q
Which security baseline includes CA-09?
A

CA-09 is included in the Maximum Security baseline (Level 3). This level is designed for high-security environments and regulated industries.

Related controls:CA-09
Q
Why is CA-09 marked as critical severity?
A

CA-09 is rated critical because failure to implement this control significantly increases the risk of security incidents. Full Zero Trust: never trust, always verify. Every access request is validated against device health, user risk, and location. This ensures compromised devices and credentials cannot access resources.

Related controls:CA-09

6

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial