AzureDevOps organization high builtIn

Description

Enable Azure Active Directory Conditional Access Policy Validation. Learn more: https://learn.microsoft.com/en-us/azure/devops/organizations/accounts/change-application-access-policies

Recommendation

1. Go to Organization Settings. 
2. Click on Security -> Policies. 
3. Security policies. 
4. Turn 'On' the setting 'Enable Azure Active Directory Conditional Access Policy Validation'.

Policy Rule

{
  "target": "ADOOrganizationPolicy",
  "if": {
    "allOf": [
      {
        "resource": "ADOOrganizationPolicy",
        "property": "Policy.Name",
        "operator": "equals",
        "value": "Policy.EnforceAADConditionalAccess"
      },
      {
        "resource": "ADOOrganizationPolicy",
        "property": "Policy.Value",
        "operator": "equals",
        "value": true
      }
    ]
  },
  "then": {
    "effect": "Audit"
  }
}