← cd ~/tools
// tools/ca
Conditional Access visualiser
Export your Conditional Access policies and load them here. Each policy is shown as a plain-English card, and the whole set is checked against a sensible baseline.
Runs entirely in your browser. Nothing you paste is sent anywhere.
1. Export your policies
Read-only. Needs Policy.Read.All (Global Reader or Security Reader is enough).
Connect-MgGraph -Scopes "Policy.Read.All"
Get-MgIdentityConditionalAccessPolicy -All | ConvertTo-Json -Depth 10 | Out-File ca-policies.json
# optional: named locations, so they show by name
Get-MgIdentityConditionalAccessNamedLocation -All | ConvertTo-Json -Depth 10 | Out-File ca-locations.jsonGraph Explorer works too: GET https://graph.microsoft.com/v1.0/identity/conditionalAccess/policies, then copy the response.
You can load the policies and named locations files together.
Groups and users show as IDs because the export doesn't include their names. The checks are this site's guidance, based on Microsoft's recommended policies, not an official assessment. See the Conditional Access cheat sheet.