Skip to content

Commit 16ec144

Browse files
committed
new unit updates for CA agent
1 parent 5d7a5b1 commit 16ec144

File tree

1 file changed

+28
-52
lines changed

1 file changed

+28
-52
lines changed
Lines changed: 28 additions & 52 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,6 @@
11

2-
3-
42
In this exercise, you explore key capabilities of the Microsoft Security Copilot Conditional Access optimization agent that is embedded in Microsoft Entra.
53

6-
**As you explore, keep in mind that unless otherwise stated, the information displayed and the configuration settings are for the currently logged in Security Administrator**.
7-
84
> [!NOTE]
95
> The environment for this exercise is a simulation generated from the product. As a limited simulation, not all links on a page are enabled and text-based inputs that fall outside of the specified script aren't supported. A pop-up stating, "This feature isn't available within the simulation" message displays. When you receive this message, select OK and continue the exercise steps.
106
>
@@ -13,26 +9,20 @@ In this exercise, you explore key capabilities of the Microsoft Security Copilot
139
1410
### Exercise
1511

16-
For this exercise, you're logged in as Avery Howard and have the Copilot owner role (security administrator role in Microsoft Entra) for the active workspace, SecurityCopilot_Workspace where you explore the key capabilities of the Microsoft Security Copilot Conditional Access optimization agent.
12+
For this exercise, you're logged in as Avery Howard and have the Copilot owner role (security administrator role in Microsoft Entra) where you explore the key capabilities of the Microsoft Security Copilot Conditional Access optimization agent. As you explore, keep in mind that the information displayed and the configuration settings are based on the Copilot owner (security administrator) role of Avery Howard.
1713

1814
This exercise should take approximately **10** minutes to complete.
1915

2016
> [!NOTE]
2117
> When a lab instruction calls for opening a link to the simulated environment, it's recommended that you open the link in a new browser window so that you can simultaneously view the instructions and the exercise environment. To do so, select the right mouse key and select the option.
2218
23-
1. Open the simulated environment by selecting [Microsoft Entra admin center](https://app.highlights.guide/start/673ccf96-b6de-43aa-b267-5c8efe51639c?token=16d48b6c-eace-4a1f-8050-098d29d23a89&azure-portal=true).
24-
19+
#### Task: Exploring the Conditional Access Agent
2520

21+
1. Open the simulated environment by selecting [Microsoft Entra admin center](https://app.highlights.guide/start/673ccf96-b6de-43aa-b267-5c8efe51639c?token=16d48b6c-eace-4a1f-8050-098d29d23a89&azure-portal=true).
2622

27-
### Option-1:
28-
1. Select the "free 60 day trial" button.
29-
1. Select **View Details** on the page:
30-
31-
### Option-2:
32-
1. Open the **Conditional Access** item in the left-side menu.
33-
2. On the **Overview** tab, select **Conditional Access Optimization Agent**.
34-
35-
### Exploring the Conditional Access Agent
23+
1. There are two ways to access the agent:
24+
1. From the left navigation panel, select **Conditional Access** then from the **Overview** tab, select **Conditional Access Optimization Agent**.
25+
1. From the main landing page of the Microsoft Entra admin center, select **Go to agents** then from the Security Copilot agents page, select **View details**.
3626

3727
1. Review the **Overview** tab.
3828

@@ -50,56 +40,42 @@ This exercise should take approximately **10** minutes to complete.
5040
1. User drift – new users were found, or user rights changed that leave them unprotected by policy.
5141
1. Policy merge – places where two or more policies could be merged to provide the same result, with easier management.
5242

53-
1. Select the breadcrumb **Conditional Access Optimization Agent** to return to the Overview page.
43+
1. From the breadcrumb, select **Conditional Access Optimization Agent** to return to the **Overview** page.
5444

55-
1. Select the Activities tab in the top menu. Review the history of when the Conditional Access Optimization agent ran and the results.
56-
57-
1. Select several different **View activity** buttons to see the progression of the Conditional Access Optimization agent as it runs each 24-hour period.
58-
59-
1. Open the second item on the list. Notice, four new applications were found, and recommended policy changes over time.
60-
61-
1. Use the breadcrumbs to return to the Overview page.
45+
1. Select the **Activities** tab in the top menu. The list shows when the agent ran, the duration of the run, the number of suggestions offer, and status. You can also view the activity map for each completed run.
46+
1. Select **View activity** to view the activity map for that run.
47+
1. Close the activity map by selecting **X**.
6248

6349
1. Select the **Suggestions** from the tab menu.
50+
1. Select the **Review suggestion** button for the first item on the list, "Add 2 users to existing policy: CA99 - Mitigate Risk Users with Password Reset."
51+
1. A panel opens to the **Policy details** tab that provides more information on the selected suggestion. The policy wants to add two users to CA99 – Mitigate Risk Users with Password Reset policy.
52+
1. Select the **Policy impact** tab at the top of the page to see a graph of this policy change over time.
53+
1. Switch back to the **Policy details** tab, then select the **Review policy changes** to see the proposed changes.
54+
1. Select the **JSON view** tab to view the JSON updates that would be applied if the suggestions were approved. The changes are highlighted.
55+
1. Close this page by selecting the **X** on the top-right corner of the page to return to the Suggestions page.
6456

65-
1. Explore the suggestion history. You have one item for each day the agent ran.
66-
67-
1. Select the **Review suggestion** button for the first item.
57+
1. Select the **Settings** tab to view information on agent settings.
6858

69-
1. Notice, the policy wants to add two users to an existing Conditional Access policy. The goal is to add users to CA99 – Mitigate Risk Users with Password Reset policy.
59+
1. Select the **X** in the upper right of the screen to return the Security Copilots agents page that shows the tile for the Conditional Access agent.
7060

71-
1. Select the **Policy impact** tab at the top of the page to see a graph of this policy change over time.
61+
1. Keep the browser tab open, you need it for the next task.
7262

73-
1. Switch back to the **Policy details** tab, then select the **Review policy changes** to see the proposed changes and the JSON update to be made.
63+
#### Task: Explore Conditional Access Optimization Agents in CA-Policies
7464

75-
1. Use the browser **Back** button to return to the **Overview** page.
65+
1. From the left navigational panel on the Microsoft Entra admin center page, select **Conditional Access** then select **Policies**.
7666

77-
1. Select **Suggestions** from the menu.
78-
79-
1. Select the **X** in the upper right of the screen to close the dialog.
80-
81-
### Explore Conditional Access Optimization Agents in CA-Policies
82-
83-
1. Open Conditional Access from the menu on the left.
84-
85-
1. Select **Policies** from the Conditional Access menu.
86-
87-
1. Review the list of policies, you should see three types:
67+
1. Review the list of policies, you should see three types (you'll need to scroll-down on the page to view all the types of policies):
8868

8969
1. Microsoft – global policies sent out by Microsoft, like require MFA.
9070
1. User – conditional access policies created by an authorized user in your organization.
9171
1. Conditional Access Optimization Agent – Report Only policies created by the agent for your review. You can choose to apply them depending on business and security goals.
9272

93-
1. Scroll down the list to find the CA99 policy we reviewed earlier.
94-
95-
1. Select the **New agent suggestion** item.
73+
1. Scroll down the list to find the "CA99 - Mitigate Risk Users with Password Reset" policy we reviewed earlier and from that line item, select **New agent suggestion**.
74+
1. This time, the information listed includes multiple suggestions. On four occasions the Conditional Access Optimization agent found new users that aren't in scope of a policy requiring a password change for high risk uses, and has an **Apply suggestion** for each.
75+
1. Select the **Apply suggestion** button for one or more of these suggestions to have the agent apply the change to the policy.
9676

97-
1. On four occasions the Conditional Access Optimization agent found new user, and has an **Apply suggestion** for each.
98-
99-
1. Read over the description of what the suggestion is going to do.
100-
101-
1. Select the **Apply suggestion** button.
77+
1. Exit Microsoft Entra to finish the simulation.
10278

103-
**Result** – The agent, monitors your users each day and found users that weren't protected by Risky User policies. It suggested you update your policy to include the new users, and provided you with a button to make the change. In one button you added protection for the users.
79+
#### Review
10480

105-
1. Exit Microsoft Entra to finish the simulation.
81+
In this exercise, you explored the Conditional Access Optimization agent. This agent scans your tenant for new users and applications and determines if Conditional Access policies are applicable, suggests updates to applicable policies, and enables quick remediation through the "Apply suggestions" option. By selecting the "Apply suggestions" button, you add protection for the impacted users and improve security for your organization.

0 commit comments

Comments
 (0)