ProcessActiveCriticalWork - Laptop, Apr 1
NEVER enforce Conditional Access policies without per-policy confirmationNEVER change CA policies from report-only to enforced without EXPLICIT per-policy confirmation. Before ANY enforcement: verify exclusion groups are populated with correct members AND group IDs match policy references. Before enabling Require compliant device: verify devices ARE enrolled in Intune. Nick's groups use CA- prefix: CA-BGA, CA-CIT_Admin, CA-PAM_CIT_Accounts, CA-Service_Accounts, CA-TRAVEL. Never batch-enforce all policies at once. One at a time, verify access after each. Treat this as a BLOCKING safety check like a destructive operation.
Applies toAllAgentsFritzNadiaAll