{"id":1546,"date":"2020-03-01T16:49:11","date_gmt":"2020-03-01T16:49:11","guid":{"rendered":"http:\/\/www.myfatblog.co.uk\/?p=1546"},"modified":"2020-03-01T16:49:11","modified_gmt":"2020-03-01T16:49:11","slug":"configuring-conditional-access-site-sensitivity","status":"publish","type":"post","link":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/","title":{"rendered":"Configuring your tenant Conditional Access for Site Sensitivity Labels in Office 365"},"content":{"rendered":"<p>In my <a href=\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/02\/site-sensitivity-labels-in-teams-groups-and-sharepoint\/\" target=\"_blank\" rel=\"noopener noreferrer\">post yesterday about the public preview of Site Sensitivity Labels in office 365<\/a>, I said I\u2019d do another post about how these work and what\u2019s required to get these working in your tenant. This is kind of important as the current documentation does NOT tell you what to configure in Conditional Access to get this working. You must also have Azure AD P1 licenses for everyone who will be subject to Site Sensitivity label as it required Azure AD Conditional Access to work.<\/p>\n<blockquote><p>Just an FYI.. you must have Azure AD P1 for anyone subject to site sensitivity labels as it requires Azure AD Conditional Access to work!<\/p><\/blockquote>\n<p>If like me you\u2019ve been using Site Scoped Conditional Access policies in SharePoint for sometime (<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-sharepoint-blog\/security-at-the-site-collection-level-in-sharepoint-online\/ba-p\/115597\">Launched in Oct 2017<\/a>!), then you may already have the required rules in Azure AD Conditional Access, as these were required to enable that functionality and these group scoped rules work in exactly the same way.<\/p>\n<p>For those of you not familiar with Conditional Access, it\u2019s a way of creating a set of policies that can be targeted at all or a subset of your users to control access to Azure AD Protected applications based on things like Who the user is, where they are logging in from, what device they are using and depending on your license even how \u201cRisky\u201d their logon is considered using AI derived algorithms.<\/p>\n<p>For the purposes of what we want to achieve, we\u2019re going to create a Conditional Access rule that covers the following key points:<\/p>\n<ol>\n<li>Is targeted at a Single Test User.<\/li>\n<li>Tests to see if the user is outside of the \u201cTrusted locations\u201d (e.g. outside the corporate perimeter)<\/li>\n<li>If the rule applies, access will be granted but final control will be passed to the application for it to control access (in this case SharePoint)<\/li>\n<\/ol>\n<p>It\u2019s that final stage that provides SharePoint the granular control over whether to allow the user in with Full or limited access, or to just block them outright. This maps directly to the ConditionalAccessPolicy property that can be configured on an SPSite object through PowerShell, with the following values.<\/p>\n<p><a href=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"image\" src=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png\" alt=\"Site Sensitivity conditional access policies\" width=\"355\" height=\"92\" border=\"0\" \/><\/a><\/p>\n<p>Looking at the sites created during both Teams creation and SharePoint site creation with sensitivity labels, I\u2019m seeing the same properties being configured under the hood, so it\u2019s safe to assume the mechanisms of both this and classic Site Scoped access policies are the same.<\/p>\n<p>These map directly to the permissions found in the Sensitivity Label configuration for Sites and Groups:<\/p>\n<p><a href=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/SNAGHTML44b4f6b8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"SNAGHTML44b4f6b8\" src=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/SNAGHTML44b4f6b8_thumb.png\" alt=\"Site Sensitivity conditional access policies settings\" width=\"383\" height=\"398\" border=\"0\" \/><\/a><\/p>\n<p>Assuming that we\u2019ve created our site sensitivity labels and created a new Team, Group or Site using them, or decorated a SharePoint site with the conditional access policy shown above, how do we create the conditional access policy to enforce those behaviours?<\/p>\n<ul>\n<li>Open the Azure Portal and find the Azure AD Conditional Access blade. Click on New Policy and configure the following:<\/li>\n<\/ul>\n<p><a href=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/SNAGHTML44b9487e.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"SNAGHTML44b9487e\" src=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/SNAGHTML44b9487e_thumb.png\" alt=\"Conditional access policy settings for Site Sensitivity\" width=\"322\" height=\"343\" border=\"0\" \/><\/a><\/p>\n<ul>\n<li>Give your new policy a meaningful name, there\u2019s a good chance your conditional access policy lists will grow quite large!<\/li>\n<li>Apply it to your test users and select which cloud apps, If you select just SharePoint, you\u2019ll see a recommendation that you use the Office 365 App as a selection instead, ignore this and Select SharePoint anyway, if you don\u2019t the Session Condition that we need is greyed out.<\/li>\n<li>Under conditions, if you have Trusted Locations configured to represent your internal perimeter devices, then configure the Conditional to EXCLUDE trusted locations. This means the policy will only apply if you are NOT in a trusted location.<\/li>\n<\/ul>\n<p><a href=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/SNAGHTML44c05daa.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"SNAGHTML44c05daa\" src=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/SNAGHTML44c05daa_thumb.png\" alt=\"Conditional access policy settings for Site Sensitivity part 2\" width=\"644\" height=\"250\" border=\"0\" \/><\/a><\/p>\n<ul>\n<li>In the Access Controls session, select the Session option and choose \u201cUse App Enforced Restrictions\u201d.<\/li>\n<li>Enable the policy and hit Create.<\/li>\n<\/ul>\n<p>Now log on with your Test user from a non trusted location and try and access sites that you\u2019ve configured with Full, Limited and Blocked access policies. You should find a mix of experiences based on each policy that you\u2019ve set.<\/p>\n<p>Note: These new policies take effect almost immediately, however if your test user has cached credentials and a valid token, they won\u2019t take effect until that token expires, so make sure you test using an InPrivate browsing session!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In my post yesterday about the public preview of Site Sensitivity Labels in office 365, I said I\u2019d do another post about how these work and what\u2019s required to get these working in your tenant. This is kind of important as the current documentation does NOT tell you what to configure in Conditional Access to &hellip; <\/p>\n<p><a class=\"more-link btn\" href=\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/\">Continue reading<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"categories":[16],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Configuring your tenant Conditional Access for Site Sensitivity Labels in Office 365 - Blog of an overweight SharePoint addict<\/title>\n<meta name=\"description\" content=\"In my post about the public preview of Site Sensitivity labels in Office 365, I said I&#039;d do a deeper dive into what&#039;s needed from Conditional Access in AAD.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Configuring your tenant Conditional Access for Site Sensitivity Labels in Office 365 - Blog of an overweight SharePoint addict\" \/>\n<meta property=\"og:description\" content=\"In my post about the public preview of Site Sensitivity labels in Office 365, I said I&#039;d do a deeper dive into what&#039;s needed from Conditional Access in AAD.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog of an overweight SharePoint addict\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-01T16:49:11+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png\" \/>\n<meta name=\"author\" content=\"Cimares\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cimares\" \/>\n<meta name=\"twitter:site\" content=\"@cimares\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Cimares\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/\",\"url\":\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/\",\"name\":\"Configuring your tenant Conditional Access for Site Sensitivity Labels in Office 365 - Blog of an overweight SharePoint addict\",\"isPartOf\":{\"@id\":\"http:\/\/www.myfatblog.co.uk\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/#primaryimage\"},\"image\":{\"@id\":\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/#primaryimage\"},\"thumbnailUrl\":\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png\",\"datePublished\":\"2020-03-01T16:49:11+00:00\",\"dateModified\":\"2020-03-01T16:49:11+00:00\",\"author\":{\"@id\":\"http:\/\/www.myfatblog.co.uk\/#\/schema\/person\/55ae8f6885bb5b8390dad001f3da83c6\"},\"description\":\"In my post about the public preview of Site Sensitivity labels in Office 365, I said I'd do a deeper dive into what's needed from Conditional Access in AAD.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/#primaryimage\",\"url\":\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png\",\"contentUrl\":\"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png\",\"width\":355,\"height\":92},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/www.myfatblog.co.uk\/#website\",\"url\":\"http:\/\/www.myfatblog.co.uk\/\",\"name\":\"Blog of an overweight SharePoint addict\",\"description\":\"The rantings of a (not so) food obsessed IT consultant!\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/www.myfatblog.co.uk\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"http:\/\/www.myfatblog.co.uk\/#\/schema\/person\/55ae8f6885bb5b8390dad001f3da83c6\",\"name\":\"Cimares\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/www.myfatblog.co.uk\/#\/schema\/person\/image\/\",\"url\":\"http:\/\/www.myfatblog.co.uk\/images\/BlogImages\/About_D057\/TopOfTheWorld.jpg\",\"contentUrl\":\"http:\/\/www.myfatblog.co.uk\/images\/BlogImages\/About_D057\/TopOfTheWorld.jpg\",\"caption\":\"Cimares\"},\"sameAs\":[\"http:\/\/www.myfatblog.co.uk\"],\"url\":\"http:\/\/www.myfatblog.co.uk\/index.php\/author\/reginald\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Configuring your tenant Conditional Access for Site Sensitivity Labels in Office 365 - Blog of an overweight SharePoint addict","description":"In my post about the public preview of Site Sensitivity labels in Office 365, I said I'd do a deeper dive into what's needed from Conditional Access in AAD.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/","og_locale":"en_US","og_type":"article","og_title":"Configuring your tenant Conditional Access for Site Sensitivity Labels in Office 365 - Blog of an overweight SharePoint addict","og_description":"In my post about the public preview of Site Sensitivity labels in Office 365, I said I'd do a deeper dive into what's needed from Conditional Access in AAD.","og_url":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/","og_site_name":"Blog of an overweight SharePoint addict","article_published_time":"2020-03-01T16:49:11+00:00","og_image":[{"url":"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png"}],"author":"Cimares","twitter_card":"summary_large_image","twitter_creator":"@cimares","twitter_site":"@cimares","twitter_misc":{"Written by":"Cimares","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/","url":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/","name":"Configuring your tenant Conditional Access for Site Sensitivity Labels in Office 365 - Blog of an overweight SharePoint addict","isPartOf":{"@id":"http:\/\/www.myfatblog.co.uk\/#website"},"primaryImageOfPage":{"@id":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/#primaryimage"},"image":{"@id":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/#primaryimage"},"thumbnailUrl":"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png","datePublished":"2020-03-01T16:49:11+00:00","dateModified":"2020-03-01T16:49:11+00:00","author":{"@id":"http:\/\/www.myfatblog.co.uk\/#\/schema\/person\/55ae8f6885bb5b8390dad001f3da83c6"},"description":"In my post about the public preview of Site Sensitivity labels in Office 365, I said I'd do a deeper dive into what's needed from Conditional Access in AAD.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/www.myfatblog.co.uk\/index.php\/2020\/03\/configuring-conditional-access-site-sensitivity\/#primaryimage","url":"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png","contentUrl":"http:\/\/www.myfatblog.co.uk\/wp-content\/uploads\/2020\/03\/image_thumb.png","width":355,"height":92},{"@type":"WebSite","@id":"http:\/\/www.myfatblog.co.uk\/#website","url":"http:\/\/www.myfatblog.co.uk\/","name":"Blog of an overweight SharePoint addict","description":"The rantings of a (not so) food obsessed IT consultant!","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/www.myfatblog.co.uk\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"http:\/\/www.myfatblog.co.uk\/#\/schema\/person\/55ae8f6885bb5b8390dad001f3da83c6","name":"Cimares","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/www.myfatblog.co.uk\/#\/schema\/person\/image\/","url":"http:\/\/www.myfatblog.co.uk\/images\/BlogImages\/About_D057\/TopOfTheWorld.jpg","contentUrl":"http:\/\/www.myfatblog.co.uk\/images\/BlogImages\/About_D057\/TopOfTheWorld.jpg","caption":"Cimares"},"sameAs":["http:\/\/www.myfatblog.co.uk"],"url":"http:\/\/www.myfatblog.co.uk\/index.php\/author\/reginald\/"}]}},"_links":{"self":[{"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/1546"}],"collection":[{"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/comments?post=1546"}],"version-history":[{"count":3,"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/1546\/revisions"}],"predecessor-version":[{"id":1549,"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/1546\/revisions\/1549"}],"wp:attachment":[{"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/media?parent=1546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/categories?post=1546"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.myfatblog.co.uk\/index.php\/wp-json\/wp\/v2\/tags?post=1546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}