Description:

Verifies that an enabled Conditional Access policy applies app-enforced restrictions to unmanaged browser sessions targeting Office 365, so idle sessions on unmanaged devices time out.

Why:

CIS M365 Foundations Benchmark v6 §1.3.2 (L2) requires that idle session timeout is enforced for unmanaged devices. A Conditional Access policy must be enabled that uses application-enforced restrictions as a session control, scoped to Office 365 apps for browser sessions on unmanaged devices (excluding compliant and Hybrid Azure AD joined devices). Note: the idle session timeout value (3 hours or less) must also be configured separately in the Microsoft 365 admin centre under Org Settings → Security & Privacy → Idle session timeout — the CA policy alone is insufficient.

Configured: An enabled Conditional Access policy enforces application-enforced restrictions for unmanaged browser sessions targeting Office 365.

Not Configured: No enabled Conditional Access policy enforces application-enforced restrictions for unmanaged browser sessions targeting Office 365.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Requires Premium (P1) licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Conditional Access Policy manager

Compliance Frameworks:

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 1.3.2

  • CIS Microsoft 365 Benchmark v7 (Level 2) — 1.3.2

Microsoft documentation: