Skip to content

Commit a3e87de

Browse files
authored
changed files by pdets auto publish service, publishid[ed531da0-9f05-404d-aea0-f76f0705b7cc] and do [publish].
1 parent 92b8336 commit a3e87de

File tree

1 file changed

+31
-31
lines changed

1 file changed

+31
-31
lines changed
Lines changed: 31 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with Zero Trust and Microsoft learning.
22

3-
The Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA). The agent will enforce device based controls (device compliance, app protection policies, and domain-joined devices). Finally, the agent can help block legacy authentication and device code flow.
3+
The Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA). The agent enforces device based controls (device compliance, app protection policies, and domain-joined devices). Finally, the agent can help block legacy authentication and device code flow.
44

55
The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies.
66

77
### Requirement to use the Conditional Access optimization agent
88

99
- You must have at least the **Microsoft Entra ID P1 license**.
10-
- You must have available **security compute units (SCU)**.
10+
- You must have available **Security Compute Units (SCU)**.
1111
- To activate the agent the first time, you need the Security Administrator or higher role.
1212
- You can assign Conditional Access Administrators with Security Copilot access.
1313
- For more information, see Assign Security Copilot access
@@ -34,10 +34,10 @@ In this exercise, you explore key capabilities in the Conditional Access optimiz
3434
**As you explore, keep in mind that unless otherwise stated, the information displayed and the configuration settings are for the currently logged in Security Administrator**.
3535

3636
> [!NOTE]
37-
> The environment for this exercise is a simulation generated from the product. As a limited simulation, not all links on a page are enabled and text-based inputs that fall outside of the specified script are not supported. A pop-up message displays stating, "This feature isn't available within the simulation." When this occurs, select OK and continue the exercise steps.
37+
> The environment for this exercise is a simulation generated from the product. As a limited simulation, not all links on a page are enabled and text-based inputs that fall outside of the specified script aren't supported. A pop-up stating, "This feature isn't available within the simulation" message displays. When you receive this message, select OK and continue the exercise steps.
3838
>
3939
>
40-
>:::image type="content" source="../media/simulation-pop-up-error.png" alt-text="Screenshot of pop-up screen indicating that this feature is not available within the simulation.":::
40+
>:::image type="content" source="../media/simulation-pop-up-error.png" alt-text="Screenshot of pop-up screen indicating that this feature isn't available within the simulation.":::
4141
4242
### Exercise
4343

@@ -46,92 +46,92 @@ For this exercise, you're logged in as Avery Howard and have the Copilot owner r
4646
This exercise should take approximately **30** minutes to complete.
4747

4848
> [!NOTE]
49-
> When a lab instruction calls for opening a link to the simulated environment, it is generally recommended that you open the link in a new browser window so that you can simultaneously view the instructions and the exercise environment. To do so, select the right mouse key and select the option.
49+
> When a lab instruction calls for opening a link to the simulated environment, it's recommended that you open the link in a new browser window so that you can simultaneously view the instructions and the exercise environment. To do so, select the right mouse key and select the option.
5050
5151

5252

5353
1. Open [https://Entra.Microsoft.com (simulation)](https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fapp.highlights.guide%2Fstart%2F673ccf96-b6de-43aa-b267-5c8efe51639c%3Ftoken%3D16d48b6c-eace-4a1f-8050-098d29d23a89&data=05%7C02%7CRobert.Stewart%40microsoft.com%7C002283d502a5447b6fc608ddb25b8a73%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638862828426563227%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=krYm%2BX%2FduKbjtZI5t27fNvWrdUIw2Vj2Ufta3fJpB0o%3D&reserved=0&azure-portal=true) with at least the Security Administrator role.
5454

5555
2. Launch the Security Copilot Agents screen:
56-
- Option-1: Select the "Try Security Copilot" agents free for 60 days
56+
- Option-1: Select the **Try Security Copilot** agents free for 60 days
5757
- Option-2: Open Conditional Access from the menu on the left. Then select the Conditional Access Optimization agent.
5858

5959
### Option-1:
60-
1. Select the free 60 day trial button.
61-
2. Select View Details on the page:
60+
1. Select the "free 60 day trial" button.
61+
2. Select **View Details** on the page:
6262

6363
### Option-2:
64-
1. Open the Conditional Access item in the left-side menu.
65-
2. On the Overview tab, select Conditional Access Optimization Agent.
64+
1. Open the **Conditional Access** item in the left-side menu.
65+
2. On the **Overview** tab, select **Conditional Access Optimization Agent**.
6666

6767
### Exploring the Conditional Access Agent
6868

69-
1. Review the Overview tab.
69+
1. Review the **Overview** tab.
7070

7171
- Agent is active – Note the last time the agent ran and the upcoming schedule.
72-
- Performance highlights – Review the cost in SCUs for the agent. See how many unprotected users the agent has found to protect.
72+
- Performance highlights – Review the cost in Security Compute Units (SCUs) for the agent. See how many unprotected users the agent found to protect.
7373
- About this agent – Quick description of the agent and how it works.
7474
- Recent suggestions – Review of all existing Conditional Access policies and suggestions on how they could be merged, updated, removed, or enhanced.
7575
- Recent Activity – Status on the last few attempts of the Conditional Access Optimization Agent to run, and the results.
7676

77-
2. In the “Agent is active” box select the “View run” link.
77+
2. Select the **View run** link within the **Agent is active** box..
7878

7979
3. Review the process flow of the agent and see what new information was detected since the last completion.
8080
- Take note that is search for three common access rights optimizations:
8181
- App / Application drift – new applications were deployed and need to be protected.
8282
- User drift – new users were found, or user rights changed that leave them unprotected by policy.
8383
- Policy merge – places where 2 or more policies could be merged to provide the same result, with easier management.
8484

85-
4. Select the breadcrumb Conditional Access Optimization Agent (Preview) at the top of the page to return to the Overview page.
85+
4. Select the breadcrumb **Conditional Access Optimization Agent** to return to the Overview page.
8686

87-
5. Select the Activities tab in the top menu. Review the history of when the Conditional Access Optimization agent has run and the results.
87+
5. Select the Activities tab in the top menu. Review the history of when the Conditional Access Optimization agent ran and the results.
8888

89-
6. Select several different View activity buttons on the right of the screen to see the progression of the Conditional Access Optimization agent as it runs each 24-hour period.
89+
6. Select several different **View activity** buttons to see the progression of the Conditional Access Optimization agent as it runs each 24-hour period.
9090

91-
7. Open the second item on the list. Note that 4 new applications were found, and recommended policy changes over time.
91+
7. Open the second item on the list. Notice, four new applications were found, and recommended policy changes over time.
9292

9393
8. Use the breadcrumbs to return to the Overview page.
9494

95-
9. Select the Suggestions from the tab menu.
95+
9. Select the **Suggestions** from the tab menu.
9696

97-
10. Explore the suggestion history. You have one item for each day the agent has been run.
97+
10. Explore the suggestion history. You have one item for each day the agent ran.
9898

99-
11. Select the Review suggestion button for the first item.
99+
11. Select the **Review suggestion** button for the first item.
100100

101-
12. Note the policy wants to add 2 users to an existing Conditional Access policy to add users to CA99 – Mitigate Risk Users with Password Reset policy.
101+
12. Notice, the policy wants to add 2 users to an existing Conditional Access policy. The goal is to add users to CA99 – Mitigate Risk Users with Password Reset policy.
102102

103-
13. Select the Policy impact tab at the top of the page to see a graph of this policy change over time.
103+
13. Select the **Policy impact** tab at the top of the page to see a graph of this policy change over time.
104104

105-
14. Switch back to the Policy details tab, then Select the “Review policy changes” to see the proposed changes and the JSON update to be made.
105+
14. Switch back to the **Policy details** tab, then Select the “Review policy changes” to see the proposed changes and the JSON update to be made.
106106

107-
15. Use the Back button in the browser to return to the Overview page.
107+
15. Use the browser **Back** button to return to the **Overview** page.
108108

109-
16. Select Suggestions from the menu.
109+
16. Select **Suggestions** from the menu.
110110

111111
17. Select the “x” in the upper right of the screen to close the dialog.
112112

113113
### Explore Conditional Access Optimization Agents in CA-Policies
114114

115115
1. Open Conditional Access from the menu on the left.
116116

117-
2. Select Policies from the CA menu.
117+
2. Select **Policies** from the Conditional Access menu.
118118

119119
3. Review the list of policies, you should see three types:
120120

121121
- Microsoft – global policies sent out by Microsoft, like require MFA.
122-
- User – conditional access polices created by an authorized user in your organization.
122+
- User – conditional access policies created by an authorized user in your organization.
123123
- Conditional Access Optimization Agent – Report Only policies created by the agent for your review. You can choose to apply them depending on business and security goals.
124124

125125
4. Scroll down the list to find the CA99 policy we reviewed earlier.
126126

127-
5. Select the New agent suggestion item.
127+
5. Select the **New agent suggestion** item.
128128

129-
6. Note that on four occasions the Conditional Access Optimization agent found new user, and has an Apply suggestion for each.
129+
6. On four occasions the Conditional Access Optimization agent found new user, and has an **Apply suggestion** for each.
130130

131131
7. Read over the description of what the suggestion is going to do.
132132

133133
8. Select the “Apply suggestion” button.
134134

135-
**Result** – The agent, has monitored your users each day and found users that we not protected by Risky User policies. It suggested that you update your policy to include the new users, and provided you with a button to make the change. In one button you have protected the users.
135+
**Result** – The agent, monitors your users each day and found users that were not protected by Risky User policies. It suggested you update your policy to include the new users, and provided you with a button to make the change. In one button you added protection for the users.
136136

137-
9. Exit out to Microsoft Entra to finish the simulation.
137+
9. Exit Microsoft Entra to finish the simulation.

0 commit comments

Comments
 (0)