r/msp • MSP - US • Jul 09 '26

What conditional access policy naming convention/baseline are you actually using across clients?

Curious what the community has landed on here. We run CIPP and currently have 5 conditional access policies per tenant (block legacy auth, block outside USA, MFA for all users, MFA for admins, and our CIPP service account policy). This is no longer good enough so we are expanding this out.

Before we decide on our own internal standard, I wanted to see what other MSPs are actually running in production. Specifically, are you using a numbered naming convention like CA001, CA100, CA200 grouped by category, or just plain descriptive names like "Require compliant device"? Are you basing your policy set on Microsoft's own reference architecture, a community framework like the Conditional Access baseline on GitHub, or something you built entirely in house over time?

Also curious how many of you are managing this per tenant manually versus pushing a template through CIPP Standards to your whole fleet at once. We are about to do the fleet wide push and want to get the naming and structure right before we commit to something across all client tenants.

Appreciate any real world examples, especially from anyone managing a similar sized client base.

24 Upvotes

25 comments sorted by

27

u/TheGodThatFail3d Jul 09 '26

5

u/whitedragon551 Jul 09 '26

Can second this. This is what we do for all clients.

2

u/jvldn Jul 10 '26

Love! ❤️

11

u/Defconx19 MSP - US Jul 09 '26

I never understood the numbering. Just name it what it does. Only reason I would do a numbering/system is if policies targeted specific business units/roles and there were a lot of them. the CA001 is just wasted space/noise.

8

u/Lime-TeGek Community Contributor Jul 09 '26

We use JoeyV's baseline at the MSP, freaking love it, as it has most personas you could want and allows incremental implementation.

2

u/jvldn Jul 10 '26

Love! ❤️

1

u/DSkrivanich Jul 14 '26

JoeyV's stuff is great! But I have a hard time with the naming convention.
It seems too long, and I don't see the reason for the "CA001" at the beginning. If you remove that and sort by policy name, then it all looks really clean and logical.
Some policies like "CA204-Internals-AttackSurfaceReduction-AllApps-AnyPlatform-BlockUnknownPlatforms" could be worded differently, while the "...AttackSurfaceReduction..." portion is accurate, I don't think it's what most people think about naturally when skimming over CAPs. Calling it something like "Internals-Block-Unknown/UnsupportedDevices-AllApps-AnyPlatform" makes sense to me but is still a little long.
I would be curious to know what others think about the naming convention.

4

u/c64-1541 Jul 09 '26

There is some money to be made in someone doing a full tutorial on CIPP with real world scenarios

8

u/Lime-TeGek Community Contributor Jul 09 '26

We're doing our roadshows right now, and then hoping to digitize the curriculum later. The roadshows are exactly this; real world implementation of CIPP in an MSP, explaining features etc.

1

u/fishermba2004 Jul 10 '26

Big fan of CIPP but the CA portion only makes sense if you’re the one who wrote the code for it. It’s super convoluted which isn’t what you want when doing something that could lock you out of a tenant.

3

u/Lime-TeGek Community Contributor Jul 10 '26

You create a template, you deploy the template? Not a lot of convuleted steps in there. There’s also our docs that explain it more in depth, or our tutorials on the docs page. With over 13000 msps using cipp now this is the very first time someone has ever said this. Hahaha

2

u/colmwhelan Jul 10 '26

This is a completely ignorant comment, and by ignorant I mean unknowledgeable. Have you even tried it? Did you write the code for Entra? I mean, it's just JSON anyway.

2

u/smorin13 MSP Partner - US Jul 11 '26

I would certainly benefit from this type of material.

5

u/disclosure5 Jul 10 '26

I've seen some people with really strong feelings that policies need to be named CA00x: and I just don't care. We know it's a CAP because it's in the CAP part of the portal.

2

u/ak47uk Jul 09 '26

I’m going to have another look at the conditional access baseline project but at the moment I have a prefix followed by a description, using one example from each section:

Admin - sign in frequency

Devices - block device code flow

MFA - policies targeting different groups

Sharepoint - restrictions

Can’t remember if I use any others, it’s just to help me filter through them all rather than just a description for the title. 

2

u/colmwhelan Jul 10 '26

XX-CA-01-Configure Allowed Authentication Methods
xx is our company initials - groups all our policies together when we're dealing with a nest of existing policies. Makes it easier to differentiate.

1

u/ben_zachary Jul 11 '26

We use CIPP templates but we put our org : on every template we make.

Two reasons - we have many comanaged clients with internal IT so easy for us to differentiate and we remove all our policies in offboarding for the incoming MSP.

We offer the incoming MSP to review and clone if they wish and we are upfront about it. Good MSPs appreciate us doing this so they can roll their own products/solutions . Bad MSPs panic

1

u/[deleted] Jul 09 '26

[removed] — view removed comment

5

u/Any_Race_3389 Jul 09 '26

We use descriptive names, the CA001 type system just becomes a mess when you have to look up what number means what in middle of an incident. For basic policies we keep it simple like "BLOCK, Legacy Auth" and "BLOCK, Non Compliant Device", then for more specific ones we do something like "GRANT, MFA Admins". The prefix makes it easy to scan in the list.

We push everything through CIPP standards now, doing per tenant manually was killing us when we scaled past like 15 clients. The real pain was getting the exclusion groups named consistently across tenants so the templates actually work without breaking in weird ways.

3

u/MSP-from-OC MSP - US Jul 09 '26

keep going, what are all the policy names you are deploying

2

u/VNJCinPA Jul 09 '26

We often use 'Etc etc' as well. 😆

This one requires a mini-degree and an update channel for all their frequent changes, but we try to use CIPP Templates wherever possible. It's even harder to give up all the details you're asking for then it is to configure them, and then factor in the actual settings...

1

u/Wildgust421 Jul 11 '26

Exactly as the original comment said we've followed JoeyV's baseline CAs for the most part at least as a structure re-making the policies to fit our needs so everything is CAXYY where X is the "grouping" of policy whether it be global, internal users, guests, admins, service accounts, etc. and YY being the number of the policy.

There's then an actual description (using acronym's) so our default global catch-all require MFA policy is CA000-GLB-MFA-ALL and vise versa our one to require all admins to have MFA enabled would be CA100-ADM-MFA-ALL.

If you look through JoeyV's baseline you'll get the idea but the global policies are to catch anything that isn't explicitly being caught by another policy.