Common/Get-CaCoverageEvidence.ps1

function Get-CaCoverageEvidence {
    <#
    .SYNOPSIS
        Identifies provable, unconditional all-user CA protection.
    .DESCRIPTION
        Exclusions and conditional targeting require assessor review. Only MFA
        required by an AND grant (or as the sole OR choice), or a built-in MFA
        authentication strength, can establish mandatory MFA. This is supporting
        configuration evidence, not a proof of Security Defaults equivalence.
    .PARAMETER Policies
        Complete set of Conditional Access policies.
    .EXAMPLE
        Get-CaCoverageEvidence -Policies $policies
    #>

    [CmdletBinding()]
    [OutputType([System.Collections.IDictionary])]
    param([Parameter()][AllowEmptyCollection()][object[]]$Policies = @())
    $coverage = [ordered]@{ 'MFA for all users' = $false; 'Legacy auth blocked' = $false; 'Admin MFA' = $false; 'Azure Management MFA' = $false }
    foreach ($policy in $Policies) {
        if ($policy.state -ne 'enabled' -or -not $policy.grantControls) { continue }
        $conditions = $policy.conditions
        $users = $conditions.users
        $apps = $conditions.applications
        if ($users.includeUsers -notcontains 'All' -or $apps.includeApplications -notcontains 'All') { continue }
        if ($users.excludeUsers -or $users.excludeGroups -or $users.excludeRoles -or $users.excludeGuestsOrExternalUsers -or
            $apps.excludeApplications -or $apps.applicationFilter) { continue }
        $restricted = $false
        foreach ($field in @('locations', 'platforms', 'devices', 'userRiskLevels', 'signInRiskLevels', 'servicePrincipalRiskLevels', 'clientApplications', 'authenticationFlows')) {
            if ($conditions.$field) { $restricted = $true }
        }
        if ($restricted) { continue }
        $grant = $policy.grantControls
        $controls = @($grant.builtInControls | Where-Object { $_ })
        $strengthMfa = $grant.authenticationStrength.id -in @(
            '00000000-0000-0000-0000-000000000002',
            '00000000-0000-0000-0000-000000000003',
            '00000000-0000-0000-0000-000000000004'
        )
        $choices = $controls.Count + @($grant.customAuthenticationFactors | Where-Object { $_ }).Count + @($grant.termsOfUse | Where-Object { $_ }).Count
        if ($grant.authenticationStrength) { $choices++ }
        $mandatory = ($controls -contains 'mfa' -or $strengthMfa) -and
            ($grant.operator -eq 'AND' -or ($grant.operator -eq 'OR' -and $choices -eq 1))
        if ($mandatory -and $conditions.clientAppTypes -contains 'all') {
            $coverage['MFA for all users'] = $true
            $coverage['Admin MFA'] = $true
            $coverage['Azure Management MFA'] = $true
        }
        if ($controls -contains 'block' -and ($conditions.clientAppTypes -contains 'all' -or
            ($conditions.clientAppTypes -contains 'exchangeActiveSync' -and $conditions.clientAppTypes -contains 'other'))) {
            $coverage['Legacy auth blocked'] = $true
        }
    }
    return $coverage
}