audit_conditional_access_policies
Audits every Conditional Access policy and flags any not in enabled state (reportOnly or disabled). Report-only policies indicate documented intent with no enforcement, a frequent audit finding.
Instructions
Audit Conditional Access policies for risks.
Lists every CA policy and flags any that aren't in enabled state (i.e.
reportOnly or disabled). Report-only policies are documented intent
that isn't actually enforcing; long-lived report-only policies are a
common audit finding.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||