Checking the documentation on this link :
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-baseline-protection#
I see that activating Baseline policy for End Users is "Free" . That's so good, but, i need to clarify what happens if we need to create a specific custom policy in order to Exclude some PowerUsers. Reading this documentation we need to add a AD P1 to those "Powerusers" in order to apply a custom Policy. But we want to maintain the Baseline Policy for all other users ( because is free ). How about this combination of policies ? If a PowerUser has applied both policies ( Baseline and Custom ) the Custom policy will win always ? also, it's a supported scenario to have the Base Line policy applied and use several Custom policies managed a AD P1 for those users ?
It will be interesting to add this scenario to the Documentation, as we have several clients asking for this :).
Thanks !
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@Aniseto Thank you for the feedback. We are actively investigating and will get back to you soon.
@MicrosoftGuyJFlo Could you please review the above scenario if it can be added to the documentation.
Conditional Access is a premium feature and requires a license. Azure AD is licensed per user. https://azure.microsoft.com/pricing/details/active-directory/
Most helpful comment
@MicrosoftGuyJFlo Could you please review the above scenario if it can be added to the documentation.