Loading...

Public Preview: Conditional Access filters for apps

Public Preview: Conditional Access filters for apps

Today we’re excited to announce the public preview of filters for apps! Filters for apps provides a new way to manage Conditional Access (CA) assignment for apps and workload identities at scale.  

 

Protecting all apps is key to achieving a Zero Trust security posture. Currently, policies explicitly list apps. With filters for apps, admins can tag applications with custom security attributes and apply Conditional Access policies based on those tags, rather than individually selecting apps. With this approach there is no limit on the number of apps covered, and new apps you add with the attributes are automatically included in the policies! Attribute assignment builds on top of custom security attributes, delivering attribute customization and a rich delegation model. 

 

Legacy conditional access policies presented numerous challenges due to sizing limitations and management of policies. The advent of filters for apps allowed us to immediately reduce the number of Conditional Access Policies by half and allows us to easily view in one location which policies are applied to an application. Filters for Apps is efficient by allowing applications to be tagged quickly and easily and is much easier to manage via MS Graph APIs.

Large private preview customer 

 

Filters for apps use the same expressions as Conditional Access filters for devices, providing a rich and familiar experience.  

 

Filter for Cloud app assignments  

Cloud app assignment supports filters for apps. You can configure filter expression rules that get evaluated when an app is accessed. When a new app is onboarded, you only need to tag it with an attribute to bring it into scope of the desired policy.  

 

For example, you can create a custom security attribute to tag apps with an app category, like HR or Finance. Apps with one of these tags will then immediately have policy enforced.   

 

sdriggers_0-1661177086538.png

 

 

Policy assignment using app attributes eliminates the chance of accidentally editing a policy when adding new apps, because only the app is updated. Additionally, custom security attribute management can be delegated to specific users. An admin can be given permission to tag apps with attributes without needing unnecessary policy management permissions. This further reduces the chance of policies being accidentally updated. 

 

Filters for workload identity assignment 

Attributes can also be applied to service principals and used with filters for apps. This is especially useful for organizations rolling out policy enforcement to hundreds or even thousands of service principals. One approach is to use custom security attributes to tag service principals authenticating from corporate network IP ranges. You can then create a policy that will block tagged service principals from authenticating from outside the corporate network. 

 

sdriggers_1-1661177086543.png

 

Try the public preview  

We’ve been working with our private preview customers - now it’s your turn to try it out and let us know what you think. Our aim is to help you more easily secure access to more of your apps and we look forward to hearing your feedback.  One way to reach us is with the “Got feedback?” link on the Conditional Access policy view. 

 

sdriggers_2-1661177086547.png

 

Conditional Access Filters for Apps 

What are custom security attributes in Azure AD? (Preview) - Azure Active Directory - Microsoft Entra | Microsoft Docs 

Filter for devices as a condition in Conditional Access policy - Azure Active Directory - Microsoft Entra | Microsoft Docs 

Azure Active Directory Conditional Access for workload identities preview - Microsoft Entra | Microsoft Docs 

 

 

Learn more about Microsoft identity: 

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Sync identities from Rippling to Microsoft Entra ID

Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...

1 year ago

Microsoft Entra ID Governance for government

I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...

1 year ago

Update to security defaults

As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...

1 year ago

Meet Microsoft Entra at Ignite 2024: November 18-22

Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...

1 year ago

Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance

I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...

1 year ago

The latest enhancements in Microsoft Authenticator

Hi folks,   I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...

1 year ago

Microsoft Security announcements and demos at Authenticate 2024

The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...

1 year ago

What's new in Microsoft Entra - September 2024

We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...

1 year ago

Explore the key benefits of Microsoft Entra Private Access

The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...

1 year ago

Join us at the Microsoft Entra Suite Showcase!

This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.