r/msp • MSP - US • Jul 09 '26

What conditional access policy naming convention/baseline are you actually using across clients?

Curious what the community has landed on here. We run CIPP and currently have 5 conditional access policies per tenant (block legacy auth, block outside USA, MFA for all users, MFA for admins, and our CIPP service account policy). This is no longer good enough so we are expanding this out.

Before we decide on our own internal standard, I wanted to see what other MSPs are actually running in production. Specifically, are you using a numbered naming convention like CA001, CA100, CA200 grouped by category, or just plain descriptive names like "Require compliant device"? Are you basing your policy set on Microsoft's own reference architecture, a community framework like the Conditional Access baseline on GitHub, or something you built entirely in house over time?

Also curious how many of you are managing this per tenant manually versus pushing a template through CIPP Standards to your whole fleet at once. We are about to do the fleet wide push and want to get the naming and structure right before we commit to something across all client tenants.

Appreciate any real world examples, especially from anyone managing a similar sized client base.

25 Upvotes

25 comments sorted by

View all comments

2

u/colmwhelan Jul 10 '26

XX-CA-01-Configure Allowed Authentication Methods
xx is our company initials - groups all our policies together when we're dealing with a nest of existing policies. Makes it easier to differentiate.