Custom Security Attributes for CA App Exclusions
Tag Enterprise Applications with a Custom Security Attribute and all relevant Conditional Access policies will automatically exclude them — no policy edits required.
Overview
The baseline uses Custom Security Attributes (CSA) to dynamically exclude applications from Conditional Access policies. Instead of hardcoding App IDs in each policy, you can simply "tag" an application and all relevant CA policies will automatically exclude it.
Exclude apps without modifying CA policies
Works with any app, including custom LOB apps
Tags are visible in the Entra portal on each app
Available Tags
IntuneComplianceExcluded Catch-all Excludes app from all Intune compliance requirements
Affects: Modern, Mobile, Browser compliance policies
ModernIntuneComplianceExcluded Excludes from desktop/modern client compliance only
Affects: MWU [MODERN] Require Intune Compliant & MFA
MobileIntuneComplianceExcluded Excludes from mobile compliance only
Affects: MWU [MOBILE] Require Intune Compliant
MobileAppProtectionExcluded Excludes from mobile app protection requirements
Affects: MWU [MOBILE] Require App Protection
BrowserIntuneComplianceExcluded Excludes from browser compliance only
Affects: MWU [BROWSER – MODERN] Require Intune Compliance
BrowserStrongAuthExcluded Excludes from browser strong auth requirements
Affects: MWU [BROWSER – MODERN] Require Strong Authentication
Tip: Use IntuneComplianceExcluded as a catch-all to exclude an app from all compliance policies except MFA.
Common Apps That Need Tagging
These Microsoft apps often need to be excluded from device compliance because they run in contexts where device compliance cannot be evaluated — for example, AVD sessions or VPN clients authenticating before a managed device is fully available.
9cdead84-a844-4324-93f2-b2e6bb768d07 IntuneComplianceExcluded 41b23e61-6c1e-4545-b367-cd054e0ed4b4 IntuneComplianceExcluded 372140e0-b3b7-4226-8ef9-d57986796201 IntuneComplianceExcluded How to Tag an Application
Prerequisites
- Entra ID P1/P2 license (for Custom Security Attributes)
- Attribute Assignment Administrator role (or Global Admin)
- The app must exist as an Enterprise Application in your tenant
Navigate to the Enterprise Application
- Go to entra.microsoft.com
- Navigate to Identity → Applications → Enterprise applications
- Search for the application by name or App ID
- Click on the application to open it
Add the Custom Security Attribute
- In the application's menu, click Properties
- Scroll down to the Custom security attributes section
- Click Add assignment
- Configure the attribute:
- – Attribute set:
BaselineCSAAppExclusions - – Attribute name:
CAExclusion - – Assigned values: Select the appropriate tag, e.g.,
IntuneComplianceExcluded
- – Attribute set:
- Click Save
Verify the Tag
- The tag should now appear under Custom security attributes on the app's Properties page
- Test sign-in to the application to verify CA policies are behaving as expected
Troubleshooting
"Custom security attributes section not visible"
- – Ensure you have Attribute Assignment Reader role at minimum to view
- – Ensure you have Attribute Assignment Administrator role to modify
"Attribute set not found"
- – The BaselineCSAAppExclusions attribute set must be deployed first — this is done automatically by the baseline pipeline
- – Check the pipeline ran with deployCustomAttributes: true
- – Verify the service principal has Attribute Definition Administrator role
"CA policy still blocking after tagging"
- – Wait 5–10 minutes for replication
- – Clear browser cache/cookies
- – Use a private/incognito window to test
- – Verify the tag value matches exactly — values are case-sensitive
Technical Details
How It Works
CA policies use an applicationFilter condition. Any application tagged with the matching attribute value is automatically excluded from the policy at evaluation time.
CustomSecurityAttribute.BaselineCSAAppExclusions_CAExclusion -contains "IntuneComplianceExcluded"
Attribute Definition
{
"attributeSet": "BaselineCSAAppExclusions",
"name": "CAExclusion",
"type": "String",
"isCollection": true,
"usePreDefinedValuesOnly": true,
"allowedValues": [
"IntuneComplianceExcluded",
"BrowserIntuneComplianceExcluded",
"BrowserStrongAuthExcluded",
"MobileAppProtectionExcluded",
"MobileIntuneComplianceExcluded",
"ModernIntuneComplianceExcluded"
]
} Required Permissions for Service Principal
For the baseline pipeline to manage Custom Security Attributes, the service principal requires the following Entra ID roles:
Create/update attribute sets and definitions
Read attributes (required for CA policy filters)
Assign attribute values to applications