All baseline controls
Identitymedium priority

Conditional access is enforced tenant-wide

Tenant-wide conditional access policy state. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

Tenant-wide conditional access policy state

A conditional access policy scoped to all users must actually be enabled, not left in report-only or disabled state — a baseline policy that is never enforced protects nobody.

Interpret the result in context

An enabled policy scoped to all users is a baseline signal. Policy exclusions, conditions and grant controls still require inspection; scope alone does not describe effective protection.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

A fixed baseline expectation

This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Identify the all-user policy and inspect its current state.

  2. 02

    Review exclusions and test the intended impact before enforcement.

  3. 03

    Enable the approved policy and verify its state after the change.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access