-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathCaBaselineScopeImpact_crowleydev_Sample.html
More file actions
186 lines (176 loc) · 20.7 KB
/
Copy pathCaBaselineScopeImpact_crowleydev_Sample.html
File metadata and controls
186 lines (176 loc) · 20.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>CA Baseline Scopes Enforcement Impact - crowley.dev</title>
<style>
:root { --ink:#1a1f2b; --sub:#5b6474; --line:#e3e7ee; --card:#ffffff; --bg:#f4f6f9; --accent:#1f4e79; }
* { box-sizing:border-box; }
body { margin:0; font-family:'Segoe UI',system-ui,sans-serif; background:var(--bg); color:var(--ink); font-size:14px; }
header { background:linear-gradient(120deg,#16324f,#1f4e79); color:#fff; padding:28px 36px; }
header h1 { margin:0 0 6px; font-size:22px; font-weight:600; }
header .meta { color:#c8d6e5; font-size:13px; }
main { max-width:1500px; margin:0 auto; padding:24px 36px 60px; }
.banner { background:#fff7ed; border:1px solid #fdba74; border-left:5px solid #ea580c; border-radius:8px; padding:14px 18px; margin:0 0 20px; }
.banner strong { color:#9a3412; }
.tiles { display:flex; gap:14px; flex-wrap:wrap; margin:0 0 24px; }
.tile { background:var(--card); border:1px solid var(--line); border-radius:10px; padding:14px 20px; min-width:170px; }
.tile .num { font-size:26px; font-weight:700; }
.tile .lbl { color:var(--sub); font-size:12px; text-transform:uppercase; letter-spacing:.04em; }
h2 { font-size:17px; margin:30px 0 10px; color:var(--accent); }
table { width:100%; border-collapse:collapse; background:var(--card); border:1px solid var(--line); border-radius:10px; overflow:hidden; }
th { text-align:left; background:#eef2f7; padding:9px 12px; font-size:12px; text-transform:uppercase; letter-spacing:.03em; color:var(--sub); border-bottom:1px solid var(--line); }
td { padding:10px 12px; border-bottom:1px solid var(--line); vertical-align:top; }
tr:last-child td { border-bottom:none; }
.sub { color:var(--sub); font-size:12px; margin-top:2px; }
.scopes { font-family:Consolas,monospace; font-size:12px; max-width:260px; word-break:break-word; }
.action { max-width:420px; }
.flags { margin-top:4px; font-size:12px; color:#9a3412; }
.empty { text-align:center; color:var(--sub); padding:22px; }
.badge { display:inline-block; padding:2px 9px; border-radius:999px; font-size:12px; font-weight:600; }
.badge.enforced { background:#dcfce7; color:#14532d; }
.badge.reportonly { background:#dbeafe; color:#1e3a5f; }
.note { color:var(--sub); font-size:13px; margin:8px 0 0; }
a { color:var(--accent); }
table.sortable thead th { cursor:pointer; user-select:none; white-space:nowrap; }
table.sortable thead th:hover { background:#e2e9f2; }
th.s-asc::after { content:' \25B2'; font-size:9px; }
th.s-desc::after { content:' \25BC'; font-size:9px; }
.tfilter { margin:0 0 8px; padding:7px 12px; border:1px solid var(--line); border-radius:8px; width:300px; font:inherit; font-size:13px; background:var(--card); }
summary { cursor:pointer; color:var(--sub); }
section.guide { background:var(--card); border:1px solid var(--line); border-radius:10px; padding:6px 20px 16px; margin-top:26px; }
section.guide li { margin:6px 0; }
</style>
</head>
<body>
<header>
<h1>Conditional Access Baseline Scopes Enforcement - Impact Report</h1>
<div class="meta">crowley.dev · Tenant c0ffee00-c0de-4bed-feed-5eed00000001 · Generated 2026-08-03 14:02 · Read-only analysis</div>
</header>
<main>
<div class="banner">
<strong>Rollout is live.</strong> Microsoft began enforcing baseline-scope evaluation for All-resources policies with exclusions on <strong>June 15, 2026</strong>, rolling out over several weeks. This tenant may already be enforced.
Manage the behavior in <a href="https://aka.ms/BaselineScopesSettingsUX" target="_blank">Baseline scope settings</a> (US Gov: <a href="https://aka.ms/BaselineScopesSettingsUX-gov" target="_blank">gov link</a>): the blade is hidden unless reached via these direct links, which append the feature.isbaselinescopesenabled flag.
Guidance: <a href="https://aka.ms/BaselineScopesSettings" target="_blank">aka.ms/BaselineScopesSettings</a> and the
<a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions" target="_blank">enforcement concept doc</a>.
</div>
<div class='banner'><strong>Tenant state: a selection is saved.</strong> A selection was saved on 2026-07-25T16:41:08.1Z with resourceAppId set to the all-zeros GUID. Field evidence maps this shape to Disable enforcement (legacy behavior retained for all policies), which Microsoft does not recommend. Confirm in the blade, which also shows if and when Microsoft's rollout enabled enforcement for this tenant.<pre style='margin:8px 0 0;font-size:12px;overflow:auto'>{
"id": "6b1a2c3d-0000-4000-8000-000000000001",
"modifiedDateTime": "2026-07-25T16:41:09.2Z",
"advancedSettings": {
"baselineScopes": {
"createdDateTime": "2026-07-25T16:41:08.1Z",
"resourceAppId": "00000000-0000-0000-0000-000000000000"
}
},
"exclusions": null
}</pre></div>
<div class="tiles">
<div class="tile"><div class="num">2</div><div class="lbl">Triggering policies</div></div>
<div class="tile"><div class="num">6</div><div class="lbl">Apps flagged Affected</div></div>
<div class="tile"><div class="num">1</div><div class="lbl">Apps to Monitor</div></div>
<div class="tile"><div class="num">1</div><div class="lbl">Unverified ISV clients</div></div>
<div class="tile"><div class="num">9</div><div class="lbl">Baseline-only clients</div></div>
<div class="tile"><div class="num">10</div><div class="lbl">Clients scanned</div></div>
<div class="tile"><div class="num">Medium</div><div class="lbl">Max enforced control</div></div>
</div>
<h2>Policies that will evaluate baseline-scope sign-ins</h2>
<table>
<tr><th>Policy</th><th>State</th><th>Why listed</th><th>Grant controls</th><th>User scope</th><th>Resource exclusions</th></tr>
<tr><td>CA001 - Require MFA for all resources</td><td><span class="badge enforced">Enabled</span></td><td>All resources + resource exclusions</td><td>Require MFA</td><td>All users (excl. 2 users, 1 groups)</td><td>Badge Photo Portal<br>TimeTrax Cloud<br>Payroll Connect<br>Office365 (app group)</td></tr>
<tr><td>CA003 - Phishing-resistant MFA for directory access</td><td><span class="badge enforced">Enabled</span></td><td>Explicitly targets Windows Azure Active Directory</td><td>Auth strength: Phishing-resistant MFA</td><td>All users</td><td></td></tr>
<tr><td>CA002 - Require compliant device (pilot)</td><td><span class="badge reportonly">Report-only</span></td><td>All resources + resource exclusions</td><td>Require compliant device</td><td>3 groups</td><td>TimeTrax Cloud</td></tr>
</table>
<p class="note">After enforcement, sign-ins that request only baseline scopes are evaluated against these policies with Windows Azure Active Directory as the audience. Report-only policies do not enforce yet but show what would apply.</p>
<h2>Client applications at risk (6)</h2>
<input class="tfilter" data-target="tblAffected" type="search" placeholder="Filter apps...">
<table class="sortable" id="tblAffected">
<thead><tr><th>Application</th><th>Client type</th><th>Ownership</th><th>Consented scopes</th><th>Verdict</th><th>Sign-ins (last 7 d)</th><th>Users</th><th>Last seen</th><th>CA failures</th><th>Recommended action</th></tr></thead>
<tbody>
<tr><td><strong>Visual Studio Code</strong><div class='sub'>aebc6443-996d-45c2-90f0-388ff96faa56 <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-000000000009/appId/aebc6443-996d-45c2-90f0-388ff96faa56' target='_blank'>Enterprise app</a></div></td><td>Public</td><td>Microsoft</td><td class='scopes'>email offline_access openid profile</td><td data-v='3'>Affected<br><span class='badge' style='background:#fcd34d;color:#402c00'>Medium</span></td><td data-v='100'>100+</td><td data-v='41'>41</td><td>2026-08-03T14:15:00Z</td><td data-v='6'>6</td><td class='action'>Interactive Microsoft client: users will start receiving the policy's challenge. Breaks where the policy blocks access or requires a managed device and devices are unmanaged, or where this client runs headless/automated. Review who uses it and from where.</td></tr>
<tr><td><strong>Lobby Kiosk Check-In</strong><div class='sub'>a9000000-0000-0000-0000-000000000001 <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-000000000001/appId/a9000000-0000-0000-0000-000000000001' target='_blank'>Enterprise app</a> · <a href='https://entra.microsoft.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/a9000000-0000-0000-0000-000000000001' target='_blank'>App registration</a></div></td><td>Public</td><td>Tenant-owned</td><td class='scopes'>openid profile User.Read</td><td data-v='3'>Affected<br><span class='badge' style='background:#fcd34d;color:#402c00'>Medium</span></td><td data-v='34'>34</td><td data-v='3'>3</td><td>2026-08-03T14:15:00Z</td><td data-v='2'>2</td><td class='action'>Confirm the app can handle Conditional Access challenges (MFA / device claims). If it cannot, update it, or retain legacy behavior for the specific policy via the Customize behavior placeholder app.</td></tr>
<tr><td><strong>Microsoft Azure CLI</strong><div class='sub'>04b07795-8ddb-461a-bbee-02f9e1bf7b46 <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-000000000008/appId/04b07795-8ddb-461a-bbee-02f9e1bf7b46' target='_blank'>Enterprise app</a></div></td><td>Public</td><td>Microsoft</td><td class='scopes'>offline_access openid profile User.Read</td><td data-v='3'>Affected<br><span class='badge' style='background:#fcd34d;color:#402c00'>Medium</span></td><td data-v='12'>12</td><td data-v='5'>5</td><td>2026-08-03T12:15:00Z</td><td data-v='0'>0</td><td class='action'>Interactive Microsoft client: users will start receiving the policy's challenge. Breaks where the policy blocks access or requires a managed device and devices are unmanaged, or where this client runs headless/automated. Review who uses it and from where.</td></tr>
<tr><td><strong>Badge Photo Portal</strong><div class='sub'>a9000000-0000-0000-0000-000000000002 <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-000000000002/appId/a9000000-0000-0000-0000-000000000002' target='_blank'>Enterprise app</a> · <a href='https://entra.microsoft.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/a9000000-0000-0000-0000-000000000002' target='_blank'>App registration</a></div><div class='flags'>Excluded from policy</div></td><td>Confidential</td><td>Tenant-owned</td><td class='scopes'>People.Read User.Read</td><td data-v='3'>Affected<br><span class='badge' style='background:#fcd34d;color:#402c00'>Medium</span></td><td data-v='9'>9</td><td data-v='4'>4</td><td>2026-08-03T12:15:00Z</td><td data-v='1'>1</td><td class='action'>Excluded confidential client consented only to baseline directory scopes: ask the developers to request OIDC scopes (openid, profile) instead of User.Read-style scopes. OIDC-only confidential clients are explicitly unaffected. Otherwise use Customize behavior.</td></tr>
<tr><td><strong>TimeTrax Cloud</strong><div class='sub'>a9000000-0000-0000-0000-000000000006 <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-000000000006/appId/a9000000-0000-0000-0000-000000000006' target='_blank'>Enterprise app</a></div><div class='flags'>Excluded from policy</div></td><td>Unknown</td><td>ISV</td><td class='scopes'>openid User.Read</td><td data-v='3'>Affected (verify client type)<br><span class='badge' style='background:#fcd34d;color:#402c00'>Medium</span></td><td data-v='3'>3</td><td data-v='1'>1</td><td>2026-08-03T09:15:00Z</td><td data-v='0'>0</td><td class='action'>Verify with the vendor whether this client handles Conditional Access challenges. If it cannot, retain legacy behavior for the specific policy via the Customize behavior placeholder app until it is fixed.</td></tr>
<tr><td><strong>Legacy Turnstile Sign-In</strong><div class='sub'>a9000000-0000-0000-0000-000000000007 <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-000000000007/appId/a9000000-0000-0000-0000-000000000007' target='_blank'>Enterprise app</a> · <a href='https://entra.microsoft.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/a9000000-0000-0000-0000-000000000007' target='_blank'>App registration</a></div><div class='flags'>Sign-in disabled</div></td><td>Public</td><td>Tenant-owned</td><td class='scopes'>openid User.Read</td><td data-v='3'>Affected<br><span class='badge' style='background:#fcd34d;color:#402c00'>Medium</span></td><td data-v='0'>0</td><td data-v='0'>0</td><td></td><td data-v='0'>0</td><td class='action'>Confirm the app can handle Conditional Access challenges (MFA / device claims). If it cannot, update it, or retain legacy behavior for the specific policy via the Customize behavior placeholder app.</td></tr>
</tbody>
</table>
<p class="note">All delegated consents (admin and per-user) were analyzed. Sign-in samples cover interactive sign-ins only, last 7 days, capped at 100 events and 40 apps. Confidential clients consented only to OIDC scopes were skipped as explicitly unaffected (1 found). Rows are sorted by recent sign-in activity, then name (unsampled rows last); click a column header to re-sort.</p>
<h2>Monitored apps (1)</h2>
<details>
<summary>Confidential clients with baseline-directory-only footprints that are NOT excluded from any triggering policy. Their Microsoft Graph sign-ins are already CA-enforced today, so no change is expected; they matter only if someone later adds them to a policy exclusion. Expand to review.</summary>
<input class="tfilter" data-target="tblMonitor" type="search" placeholder="Filter apps..." style="margin-top:10px">
<table class="sortable" id="tblMonitor" style="margin-top:6px">
<thead><tr><th>Application</th><th>Client type</th><th>Ownership</th><th>Consented scopes</th><th>Verdict</th><th>Sign-ins (last 7 d)</th><th>Users</th><th>Last seen</th><th>CA failures</th><th>Recommended action</th></tr></thead>
<tbody>
<tr><td><strong>Cafeteria Menu Web</strong><div class='sub'>a9000000-0000-0000-0000-000000000003 <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-000000000003/appId/a9000000-0000-0000-0000-000000000003' target='_blank'>Enterprise app</a> · <a href='https://entra.microsoft.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/a9000000-0000-0000-0000-000000000003' target='_blank'>App registration</a></div></td><td>Confidential</td><td>Tenant-owned</td><td class='scopes'>User.Read</td><td data-v='1'>Monitor<br><span class='badge' style='background:#dbeafe;color:#1e3a5f'>Info</span></td><td data-v='-1'></td><td data-v='-1'></td><td></td><td data-v='-1'></td><td class='action'>Not excluded from any triggering policy, so its Microsoft Graph sign-ins are already CA-enforced today; no change expected. Listed because its footprint is baseline-directory-only: if it is ever added to an exclusion, it lands in the affected set.</td></tr>
</tbody>
</table>
</details>
<h2>Unverified ISV clients (1)</h2>
<details>
<summary>These baseline-only ISV apps are not excluded from any triggering policy and their client type cannot be determined from this tenant. Most are web SSO integrations (confidential, unaffected); any that are native or desktop clients are affected. Expand to review; sign-in activity helps separate live apps from dormant entries.</summary>
<input class="tfilter" data-target="tblPossible" type="search" placeholder="Filter apps..." style="margin-top:10px">
<table class="sortable" id="tblPossible" style="margin-top:6px">
<thead><tr><th>Application</th><th>Client type</th><th>Ownership</th><th>Consented scopes</th><th>Verdict</th><th>Sign-ins (last 7 d)</th><th>Users</th><th>Last seen</th><th>CA failures</th><th>Recommended action</th></tr></thead>
<tbody>
<tr><td><strong>MuralBoard</strong><div class='sub'>a9000000-0000-0000-0000-00000000000a <a href='https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/5e000000-0000-0000-0000-00000000000a/appId/a9000000-0000-0000-0000-00000000000a' target='_blank'>Enterprise app</a></div></td><td>Unknown</td><td>ISV</td><td class='scopes'>openid profile User.Read</td><td data-v='2'>Possible<br><span class='badge' style='background:#dbeafe;color:#1e3a5f'>Low</span></td><td data-v='6'>6</td><td data-v='2'>2</td><td>2026-08-03T12:15:00Z</td><td data-v='0'>0</td><td class='action'>Affected only if this is actually a public (native or desktop) client. Multi-tenant web SSO integrations are confidential clients and are unaffected unless excluded from an All-resources policy. If users reach this app through a desktop or mobile client that requests only these scopes, treat it as Affected; sign-in activity below helps triage dormant entries.</td></tr>
</tbody>
</table>
</details>
<section class="guide">
<h2>How to read this and what to do</h2>
<ul>
<li><strong>Baseline scopes:</strong> openid, profile, email, offline_access, User.Read, User.Read.All, User.ReadBasic.All, People.Read, People.Read.All, GroupMember.Read.All, Member.Read.Hidden.</li>
<li><strong>Affected public clients</strong> break (or start prompting) regardless of policy exclusions. Interactive apps on compliant devices mostly just see a new MFA prompt; headless or kiosk usage, unmanaged devices under a compliant-device control, and anything under a block control will fail.</li>
<li><strong>Affected confidential clients</strong> (excluded + baseline directory scopes only) have a clean fix: switch the app to OIDC scopes (openid, profile). OIDC-only confidential clients are explicitly unaffected.</li>
<li><strong>To keep an exemption on purpose:</strong> use <em>Customize behavior</em> in the <a href="https://aka.ms/BaselineScopesSettingsUX" target="_blank">Baseline scopes settings</a>: register a placeholder single-tenant app, exclude it from the specific policy, and select it as the baseline-scopes target resource. That retains legacy behavior for that policy only. Disabling enforcement tenant-wide is not recommended.</li>
<li><strong>Authoritative detection:</strong> this report infers "requests only baseline scopes" from consent footprints, which is static evidence. Apps that were never consented in this tenant, or whose runtime requests differ from their consents, are not visible here. Microsoft's authoritative method: configure Customize behavior with a placeholder app, then filter sign-in logs on <code>conditionalAccessAudiences</code> for that app id over several days.</li>
<li><strong>Not in scope of this change:</strong> app-only (client credentials) tokens, apps requesting any scope beyond baseline (already enforced), and All-resources policies without exclusions.</li>
</ul>
</section>
</main>
<script>
(function () {
function cellVal(row, idx) {
var cell = row.cells[idx];
if (!cell) { return ''; }
if (cell.hasAttribute('data-v')) { return parseFloat(cell.getAttribute('data-v')); }
var t = cell.textContent.trim();
var n = parseFloat(t.replace(/[^0-9.\-]/g, ''));
if (t !== '' && !isNaN(n) && /^[0-9]/.test(t)) { return n; }
return t.toLowerCase();
}
document.querySelectorAll('table.sortable thead th').forEach(function (th) {
th.addEventListener('click', function () {
var table = th.closest('table');
var tbody = table.tBodies[0];
var idx = Array.prototype.indexOf.call(th.parentNode.children, th);
var dir = th.dataset.dir === 'desc' ? 'asc' : 'desc';
table.querySelectorAll('thead th').forEach(function (h) { delete h.dataset.dir; h.classList.remove('s-asc', 's-desc'); });
th.dataset.dir = dir;
th.classList.add(dir === 'asc' ? 's-asc' : 's-desc');
var rows = Array.prototype.slice.call(tbody.rows);
rows.sort(function (a, b) {
var va = cellVal(a, idx), vb = cellVal(b, idx);
if (typeof va === 'number' && typeof vb === 'number') { return dir === 'asc' ? va - vb : vb - va; }
va = String(va); vb = String(vb);
return dir === 'asc' ? va.localeCompare(vb) : vb.localeCompare(va);
});
rows.forEach(function (r) { tbody.appendChild(r); });
});
});
document.querySelectorAll('input.tfilter').forEach(function (inp) {
inp.addEventListener('input', function () {
var table = document.getElementById(inp.dataset.target);
if (!table) { return; }
var q = inp.value.toLowerCase();
Array.prototype.forEach.call(table.tBodies[0].rows, function (r) {
r.style.display = r.textContent.toLowerCase().indexOf(q) === -1 ? 'none' : '';
});
});
});
})();
</script>
</body>
</html>