Default Block All rule in conditional access
White List + Block All rules combination would be easy to create. In current CA, customer hate to create tons of {Access 1, Block 1} rule pairs.

3 comments
-
Samir Sultanali commented
This should work as a firewall policy, with a default block rule with a fail safe rule like always allowing global admins to log into azure portal from trusted IPs.
-
Jack commented
Make a block rule for everything. Do not block yourself out...
-
Henrik Skovgaard commented
Make it possible to have Conditional Access block everything by default, and then you need to open up for access instead of everything being granted access if you don't configure anything.