Conditional Access Policy Timeline and Restore Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack efficient management and protection of conditional access policies across multiple organizations and tenants, leading to challenges in identifying changes, preventing unauthorized modifications, and ensuring secure backup and restoration of these policies.

Innovation Solution

A cloud security system that manages and protects conditional access policies by providing a user interface for policy selection, a timeline of changes, and automated backup and restoration, using tools like Microsoft Graph to export and analyze policy changes, and implementing an approval workflow for policy modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If administrators manage conditional access policies across multiple organizations and tenants, then access control coverage is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments policy management by organization and tenant, allowing administrators to manage conditional access policies across multiple organizations and tenants through a unified interface. Each organization and tenant has isolated policy scopes, enabling comprehensive coverage while maintaining manageable structure through hierarchical organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The conditional access policy management system provides universal functionality across multiple organizations and tenants. A single system instance can manage policies for numerous tenants simultaneously, providing multi-tenant support with unified policy creation, modification, and monitoring capabilities that work across all organizations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If automated backup and restoration of policies is implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvepolicy backup reliabilityVSAvoidbackup system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary backup actions automatically, creating point-in-time snapshots of conditional access policies before changes occur. This proactive backup approach ensures policy states are preserved without requiring manual intervention, improving reliability while the automation handles the complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The backup and restoration mechanism operates autonomously, automatically backing up policies and enabling restoration without requiring administrator intervention. The system self-manages the backup process, maintaining reliability while shielding users from backup system complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If approval workflow for policy changes is implemented, then unauthorized changes are prevented, but operational efficiency decreases

Engineering Contradiction:
Improveunauthorized change preventionVSAvoidpolicy modification efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The approval workflow introduces feedback mechanisms where policy change requests are reviewed and approved by authorized personnel before implementation. This feedback loop prevents unauthorized changes while the streamlined process maintains operational efficiency through automated notifications and clear approval workflows.

Inventive Principle:
Principle #23Feedback

4Difficulty of detecting and measuring

If timeline of policy changes is tracked and displayed, then change identification is improved, but information processing complexity increases

Engineering Contradiction:
Improvechange identificationVSAvoidchange tracking complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system preliminarily tracks and records all policy changes with timestamps, creating a chronological timeline that automatically documents what changed, when it changed, and by whom. This preliminary recording simplifies change identification by organizing data in advance rather than requiring complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the policy change history as a timeline display, presenting past policy states in an organized chronological format. This copied historical record makes change identification straightforward by providing a clear audit trail without requiring complex real-time tracking during policy modifications.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250385942A1Handling of Conditional Access Policies
Publication Date: 2025.12.18 PRO-VISION SOFTWARE SOLUTIONS LTD
  • US20250385942A1 patent drawing
  • US20250385942A1 patent drawing
  • US20250385942A1 patent drawing

AI summary

A conditional access policy management system which enables organizations' administrators to manage conditional access policies controlling user access to respective organizational assets, e.g., apps which respective organizations may store on a cloud, the system comprising a user interface enabling an administrator to select a policy, to define a selected policy; and/or a processor which may be configured to display a timeline along which a sequence of plural time-points may be arranged wherein changes were made in said selected policy at each of the plural time-points.