Description:
Verifies if a Conditional Access Policy is in place that blocks access based on IP address.
Make sure your Named Locations is set with Location Type: IP Ranges.
Why:
Having a risky IP address conditional access policy defined reduces the number of attacks users are exposed to. This can be done through requiring additional steps to grant access from certain IP addresses or blocking access completely.
Configured: Policy is in place.
Not Configured: Policy is not in place.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: Guided remediation steps (Instructions tab); Conditional Access Policy manager
Compliance Frameworks:
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.2.14
CMMC Level 2 — AC.L2-3.1.12, SI.L2-3.14.6, SI.L2-3.14.7
Microsoft documentation:
_KB status: already published as "Risky IP Address Policy" — update the existing step in place._
_Source: Augmentt native check. Check ID riskyips (module 12)._
Sourced for this page:
Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Identity · Entra ID P1 · CIS M365 v7 L1 · CMMC Level 2
