Traveling Employee CA Policy Crate
If you’re new to Crates, read through our introductory Crate documentation here. Find the Crate in our Crate Marketplace.
What does the Traveling Employee CA Policy Crate do?
This Crate allows MSPs to easily manage traveling employees and their access via a form to adjust conditional access policies automatically upon their departure and return dates. Technicians and customers can self-serve, reducing tickets and time spent on these types of requests.
This Crate doesn't permanently modify existing conditional access policies, manage trusted locations, or approve or deny travel requests.
How the Crate works
This Crate contains three separate forms.
[REWST] M365: Traveling Employee CA Policy - Setup is used once or rarely to set your base level of conditional access policy.
[REWST] M365: Traveling Employee CA Policy (MSP) is used any time you want to prepare for a traveling employee or bucketed group of traveling employees. This form inherits the policies set with the first form.
[REWST] M365: Traveling Employee CA Policy (Self-Serve) is meant to be sent to individual users to have them fill out the travel plans for themselves or their group of employees.
The Crate's workflow runs on a cron trigger. It checks once daily for users indicated by the form, and adds them to an exclusion list. Access is granted only for the approved travel window and revoked automatically. Only configured baseline block policies are bypassed during travel. All other active CA policies, such as MFA requirements, remain. Temporary resources are automatically deleted after use.
PSA tickets are created and updated any time the MSP or Self-Serve forms are submitted.

In the event of travel delays, such as rescheduled flights or weather-related incidents that move the initially indicated end date to further in the future, there is no way to adjust the existing policy. Instead, delete the policy. Then, use the [REWST] M365: Traveling Employee CA Policy (MSP) form to create a new one with the new, further-in-the-future date.
Crate prerequisites
Before unpacking this Crate, you must first have:
Your PSA successfully integrated with Rewst
Our Microsoft Cloud integration bundle successfully integrated with Rewst
Unpack the Traveling Employee CA Policy Crate
Navigate to Crates > Crate Marketplace in the left side menu of the Rewst platform.
Search for
Traveling Employee CA Policy.
Click on the Crate tile to begin unpacking.
Click Unpack Crate.
Click Continue.
Ensure that all triggers are set to Enabled.
Click Unpack.
Use the Crate
Set your conditional access policy guidelines with the [REWST] M365: Traveling Employee CA Policy - Setup form
Navigate to Automations > Forms.
Search for
[REWST] M365: Traveling Employee CA Policy - Setup.Click ⋮ > Usages > View Direct URLs.
Click on the relevant link to launch it for your desired organization.
Select an organization to set the policy for from the Organization drop-down selector.
Use the Baseline Block Policies drop-down to select all policies that may block a traveling user. Selected policies will have users added to their exclusion list during the approved travel time window to allow access.
Click Submit.

As needed, prepare for employee travel with the [REWST] M365: Traveling Employee CA Policy (MSP) form
We recommend filling out one test of the form after you first set your policy guidelines to ensure that the ticket is properly created in your PSA.
Navigate to Automations > Forms.
Search for
[REWST] M365: Traveling Employee CA Policy (MSP).Click ⋮ > Usages > View Direct URLs.
Click on the relevant link to launch it for your desired organization.
Select an organization to set the policy for from the Organization drop-down selector.
Use the following fields to enter information about the travel plan:
Ticket - Select an existing ticket to update, otherwise a new ticket will be created in your PSA at the time of submission
Users - Select the user or users who require a travel conditional access policy to be applied
Destination Countries - Select the countries the user or users will be traveling to
Departure Date - Enter the date and time the user or users will begin travel, which is when the conditional access policy will take effect
Return Date - Enter the date and time the user or users will return from travel, which is when the conditional access policy will be removed
Click Submit.

As needed, prepare for employee travel with the [REWST] M365: Traveling Employee CA Policy (Self-Serve) form
Navigate to Automations > Forms.
Search for
[REWST] M365: Traveling Employee CA Policy (Self-Serve).Click ⋮ > Usages > View Direct URLs.
Click on the relevant link to launch it for your desired organization.
Use the following fields to enter information about the travel plan:
Ticket - Select an existing ticket to update, otherwise a new ticket will be created in your PSA at the time of submission
Users - Select the user or users who require a travel conditional access policy to be applied
Destination Countries - Select the countries the user or users will be traveling to
Departure Date - Enter the date and time the user or users will begin travel, which is when the conditional access policy will take effect
Return Date - Enter the date and time the user or users will return from travel, which is when the conditional access policy will be removed
Click Submit.

Organization variables associated with this Crate
For more on organization variables and how to use them, see our org variable documentation here.
Organization variables not found in our standard organization variables documentation, such as the ones listed below. are typically system variables that are handled by integration mappings.
If you haven't done so already, we recommended that you run the Configure Organization Variables Crate, which will help you set org variables that are relevant to you and your customer's environments.
These variables are system-managed and must not be modified manually. All configuration should be done via the setup form unpacked with this Crate.
traveling_employee_users_group: Reference to the traveling users group used for CA policy exclusions.traveling_employee_block_policies: References to baseline blocking CA policies from which traveling users are excluded during travel.traveling_employee_policy_tickets: Links travel-specific CA policies to tickets for automated updates throughout the travel lifecycl
Got an idea for a new Crate? Rewst is constantly adding new Crates to our Crate Marketplace. Submit your idea or upvote existing ideas here in our Canny feedback collector.
Last updated
Was this helpful?

