CA-12: Conditional Access for Workload Identities

Frequently asked questions about implementing and managing the CA-12 security control in Microsoft 365 and Entra ID.

Q
What is CA-12 (Conditional Access for Workload Identities)?
A

CA-12 is a security control that service principals authenticate without user interaction and often have broad permissions. without ca policies, a compromised service principal has unrestricted access. workload identity ca policies enable location-based and risk-based controls for non-human identities. It requires that a conditional access policy targets service principal authentication and high-risk workload identities are covered by risk-based policies, policy is in enforced (not report-only) state.

Related controls:CA-12
Q
Why is Conditional Access for Workload Identities important for Microsoft 365 security?
A

Service principals authenticate without user interaction and often have broad permissions. Without CA policies, a compromised service principal has unrestricted access. Workload identity CA policies enable location-based and risk-based controls for non-human identities.

Related controls:CA-12
Q
How do I implement CA-12 in my tenant?
A

TrueConfig provides one-click remediation for CA-12. Creates CA policy targeting workload identities in report-only mode. Requires Workload Identities Premium license.

Related controls:CA-12
Q
What license do I need for CA-12?
A

This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.

Related controls:CA-12
Q
Which security baseline includes CA-12?
A

CA-12 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.

Related controls:CA-12

5

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial