1588 - Entra ID: Supported attributes for Conditional Access policies

Modified on Tue, 5 Aug at 1:09 PM

This article lists the attributes that are protected as part of Conditional Access policies in Entra ID. For supported attributes related to other objects, see "What is supported?" in Article 1554.

 

Page contents

 

Please take note of the following limitations with regard to recovery:

  • Whenever you recover Entra ID objects in the RedApp, you may be asked to re-authenticate with Microsoft.
  • With regard to relationships, we backup and recover only the supported relationships listed here.

 

Supported attributes: Conditional Access policies

AttributeDescriptionBacked upRestorable
idSpecifies the identifier of the object. Read-only.YesNo
descriptionDescription of the object. Not used.NoNo
displayNameSpecifies a display name for the object.YesYes
createdDateTimeThe Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. Read-only.YesYes
modifiedDateTimeThe Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. Read-only.YesYes
stateSpecifies the state of the object. RequiredYesYes
ConditionsSpecifies the rules that must be met for the policy to apply. Required.YesYes
grantControlsSpecifies the grant controls that must be fulfilled to pass the policy.YesYes
sessionControlsSpecifies the session controls that must be fulfilled to pass the policy.YesYes


Supported relationships

grantControls - authentication strengths

 

Supported attributes: authentication strengths

Note: Built-in authentication strengths are not supported because they are immutable (i.e. they cannot be created, changed or deleted) and have no relationships to other objects. Only custom authentication strengths are backed up.

AttributeDescriptionBacked upRestorable
allowedCombinationsA collection of authentication method modes that are required be used to satisfy this authentication strength.YesYes
createdDateTimeThe datetime when this policy was createdYesYes
descriptionThe human-readable description of this policy.YesYes
displayNameThe human-readable display name of this policy.YesYes
idThe system-generated identifier for this mode. Inherited from entity.YesNo
modifiedDateTimeThe datetime when this policy was last modified.YesYes
policyTypeA descriptor of whether this policy is built into Microsoft Entra Conditional Access or created by an admin for the tenant.YesNo
requirementsSatisfiedA descriptor of whether this authentication strength grants the MFA claim upon successful satisfaction.YesNo


Supported relationships

combinationConfigurations

 

Supported attributes: country named locations

AttributeDescriptionBacked upRestorable
countriesAndRegionsList of countries and/or regions in two-letter format specified by ISO 3166-2.YesYes
countryLookupMethodDetermines what method is used to decide which country the user is located in.YesYes
createdDateTimeThe Timestamp type represents creation date and time of the location using ISO 8601 format and is always in UTC time. Read-only. Inherited from namedLocation.YesNo
displayNameHuman-readable name of the location. Required. Inherited from namedLocation.YesYes
idIdentifier of a namedLocation object. Read-only. Inherited from namedLocation.YesNo
includeUnknownCountriesAndRegionsTrue if IP addresses that don't map to a country or region should be included in the named location. Optional.YesYes
modifiedDateTimeThe Timestamp type represents last modified date and time of the location using ISO 8601 format and is always in UTC time. Read-only. Inherited from namedLocation.YesNo

 

 

Supported attributes: IP named locations

AttributeDescriptionBacked upRestorable
createdDateTimeThe Timestamp type represents creation date and time of the location using ISO 8601 format and is always in UTC time. Read-only. Inherited from namedLocation.YesNo
displayNameHuman-readable name of the location. Required.YesYes
idIdentifier of a namedLocation object. Read-only. Inherited from namedLocation.YesNo
ipRangesList of IP address ranges in IPv4 CIDR format (for example, 1.2.3.4/32) or any allowable IPv6 format from IETF RFC5969. Required.YesYes
isTrustedtrue if this location is explicitly trusted. Optional.YesYes
modifiedDateTimeThe Timestamp type represents last modified date and time of the location using ISO 8601 format and is always in UTC time. Read-only. Inherited from namedLocation.YesNo

 

 

Supported attributes: compliant network named locations

AttributeDescriptionBacked upRestorable
compliantNetworkTypeType of compliant network. Currently the only possible value is allTenantCompliantNetworks.YesYes
createdDateTimeThe timestamp type represents creation date and time of the location using ISO 8601 format and is always in UTC time. Read-only. Inherited from namedLocation.YesNo
displayNameHuman-readable name of the location. Required. Always "All Compliant Network Locations". Inherited from namedLocation.YesYes
idIdentifier of the object. Read-only. Inherited from entityYesNo
isTrustedTrue if this location is explicitly trusted. Optional. Default value is false.YesYes
modifiedDateTimeThe timestamp type represents last modified date and time of the location using ISO 8601 format and is always in UTC time. Read-only. Inherited from namedLocation.YesYes

 

 

Supported attributes: authentication contexts

AttributeDescriptionBacked upRestorable
idIdentifier used to reference the authentication context class.YesNo
displayNameA friendly name that identifies the authenticationContextClassReference object when building user-facing admin experiences.YesYes
DescriptionA short explanation of the policies that are enforced by authenticationContextClassReference.YesYes
isAvailableIndicates whether the authenticationContextClassReference has been published by the security admin and is ready for use by apps.YesYes

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article