Need to create Conditional Access Policy for Certificate Based authentication

ShashankSaxena-2458 131 Reputation points
2023-12-07T04:36:03.0233333+00:00

Hello All,

I am attempting to establish a Conditional Access Policy for users using Certificate Based Authentication. I want to enable Certificate Based Authentication(Passwordless) for users accessing specific applications from outside the company network, while allowing normal authentication(username and password) for internal access. Is there a method to accomplish this, and if so, how can it be done?

Regards,

Shashank Saxena

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
649 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,742 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,365 questions
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 30,251 Reputation points Microsoft Employee
    2023-12-07T06:24:00.48+00:00

    @ShashankSaxena-2458 Thank you for reaching out to us, As I understand you want to implement Conditional Access Policy for users using Certificate Based Authentication.

    You can achieve this using authentication strength, though we have built-in authentication strengths however you can create a custom authentication strength - https://video2.skills-academy.com/en-us/entra/identity/authentication/concept-authentication-strengths#:~:text=policyType%20eq%20%27builtIn%27-,Custom%20authentication%20strengths,-In%20addition%20to use the same in the Grant controls section of conditional access policy.

    Refer to this https://hmaslowski.com/f/azure-ad-certificate-based-authentication-cba-in-public-preview where similar requirement has been deployed.

    https://video2.skills-academy.com/en-us/entra/identity/authentication/concept-certificate-based-authentication

    Also, make sure you test this with pilot users/report only mode, before setting up in production.

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful