MOCKUP — E - CA Policies · Phase 2 · security · identity · Follow REPORT-DESIGN-SPEC.md in Power BI Desktop to build this
Cq Claritiq · E - CA Policies Refreshed today
Critical Caution Healthy · target
Scope: eni.enigron.com · c1.eni.enigron.com
Total policies
27
across 6 categories
Enabled
21
77.8%
Report-only
4
≥ 30d in this state
Disabled
2
review intent
Overlap pairs
3
redundant rules
MFA gap users
47
not covered by any MFA-required policy
Policies × state
CategoryEnabledReport-onlyDisabledTotal
MFA enforcement810
9
Block legacy auth300
3
Device compliance411
6
Risk-based sign-in210
3
Privileged role guard300
3
Location filter111
3
Overlap & gap findings
FindingAffectedSeverity
Overlap: 'MFA-AllUsers' + 'MFA-AllApps'(both)Caution
Overlap: 'Block-Legacy-Outlook' + 'Block-Legacy-EWS'(both)Caution
Gap: 47 users not covered by MFA-required47Critical
Stale: 4 policies in report-only > 30d4Caution
Stale: 2 disabled policies (no recent edits)2Caution
CA policy overlap creates evaluation noise; gaps create exposure. Quarterly access-review export should include this matrix.
Quick views
All CA policies — inventory snapshot Showing 6 of 27 · Sorted by Category, Name
Policy nameStateUsers targetAppsConditionsGrantLast modified
MFA-AllUsersEnabledAll usersAll cloud appsAny deviceRequire MFA2025-11-04
MFA-AllAppsEnabledAll usersAll cloud appsAny platformRequire MFA2024-09-12
Block-Legacy-OutlookEnabledAll usersOffice 365Legacy authBlock2024-04-22
Risk-Based-SignIn-HighEnabledAll usersAll cloud appsHigh user riskRequire MFA + reset2025-08-14
Privileged-Role-GuardEnabledTier-0 adminsAll cloud appsAnyCompliant device + FIDO22025-12-11
Location-EU-OnlyDisabledEU subsidiaryAll cloud appsOutside EUBlock2023-06-04