Conditional Access

Custom Security Attributes for CA App Exclusions

Tag Enterprise Applications with a Custom Security Attribute and all relevant Conditional Access policies will automatically exclude them — no policy edits required.

2 min read Updated December 5, 2025

Overview

The baseline uses Custom Security Attributes (CSA) to dynamically exclude applications from Conditional Access policies. Instead of hardcoding App IDs in each policy, you can simply "tag" an application and all relevant CA policies will automatically exclude it.

Flexibility

Exclude apps without modifying CA policies

Scalability

Works with any app, including custom LOB apps

Auditability

Tags are visible in the Entra portal on each app

Available Tags

IntuneComplianceExcluded Catch-all

Excludes app from all Intune compliance requirements

Affects: Modern, Mobile, Browser compliance policies

ModernIntuneComplianceExcluded

Excludes from desktop/modern client compliance only

Affects: MWU [MODERN] Require Intune Compliant & MFA

MobileIntuneComplianceExcluded

Excludes from mobile compliance only

Affects: MWU [MOBILE] Require Intune Compliant

MobileAppProtectionExcluded

Excludes from mobile app protection requirements

Affects: MWU [MOBILE] Require App Protection

BrowserIntuneComplianceExcluded

Excludes from browser compliance only

Affects: MWU [BROWSER – MODERN] Require Intune Compliance

BrowserStrongAuthExcluded

Excludes from browser strong auth requirements

Affects: MWU [BROWSER – MODERN] Require Strong Authentication

Tip: Use IntuneComplianceExcluded as a catch-all to exclude an app from all compliance policies except MFA.

Common Apps That Need Tagging

These Microsoft apps often need to be excluded from device compliance because they run in contexts where device compliance cannot be evaluated — for example, AVD sessions or VPN clients authenticating before a managed device is fully available.

Azure Virtual Desktop
9cdead84-a844-4324-93f2-b2e6bb768d07
IntuneComplianceExcluded
Azure VPN
41b23e61-6c1e-4545-b367-cd054e0ed4b4
IntuneComplianceExcluded
Azure Windows VM Sign-In
372140e0-b3b7-4226-8ef9-d57986796201
IntuneComplianceExcluded

How to Tag an Application

Prerequisites

  • Entra ID P1/P2 license (for Custom Security Attributes)
  • Attribute Assignment Administrator role (or Global Admin)
  • The app must exist as an Enterprise Application in your tenant
1

Navigate to the Enterprise Application

  1. Go to entra.microsoft.com
  2. Navigate to Identity → Applications → Enterprise applications
  3. Search for the application by name or App ID
  4. Click on the application to open it
2

Add the Custom Security Attribute

  1. In the application's menu, click Properties
  2. Scroll down to the Custom security attributes section
  3. Click Add assignment
  4. Configure the attribute:
    • – Attribute set: BaselineCSAAppExclusions
    • – Attribute name: CAExclusion
    • – Assigned values: Select the appropriate tag, e.g., IntuneComplianceExcluded
  5. Click Save
3

Verify the Tag

  1. The tag should now appear under Custom security attributes on the app's Properties page
  2. Test sign-in to the application to verify CA policies are behaving as expected

Troubleshooting

"Custom security attributes section not visible"

  • – Ensure you have Attribute Assignment Reader role at minimum to view
  • – Ensure you have Attribute Assignment Administrator role to modify

"Attribute set not found"

  • – The BaselineCSAAppExclusions attribute set must be deployed first — this is done automatically by the baseline pipeline
  • – Check the pipeline ran with deployCustomAttributes: true
  • – Verify the service principal has Attribute Definition Administrator role

"CA policy still blocking after tagging"

  • – Wait 5–10 minutes for replication
  • – Clear browser cache/cookies
  • – Use a private/incognito window to test
  • – Verify the tag value matches exactly — values are case-sensitive

Technical Details

How It Works

CA policies use an applicationFilter condition. Any application tagged with the matching attribute value is automatically excluded from the policy at evaluation time.

applicationFilter syntax
CustomSecurityAttribute.BaselineCSAAppExclusions_CAExclusion -contains "IntuneComplianceExcluded"

Attribute Definition

{
  "attributeSet": "BaselineCSAAppExclusions",
  "name": "CAExclusion",
  "type": "String",
  "isCollection": true,
  "usePreDefinedValuesOnly": true,
  "allowedValues": [
    "IntuneComplianceExcluded",
    "BrowserIntuneComplianceExcluded",
    "BrowserStrongAuthExcluded",
    "MobileAppProtectionExcluded",
    "MobileIntuneComplianceExcluded",
    "ModernIntuneComplianceExcluded"
  ]
}

Required Permissions for Service Principal

For the baseline pipeline to manage Custom Security Attributes, the service principal requires the following Entra ID roles:

Attribute Definition Administrator

Create/update attribute sets and definitions

Attribute Definition Reader

Read attributes (required for CA policy filters)

Attribute Assignment Administrator

Assign attribute values to applications