Last updated: April 29, 2026
Conditional Access = Entra ID’s policy engine. The single highest-leverage security control in any Microsoft-shop enterprise.
The if-then structure
If [signals] then [decision].
Signals
- User / group
- Cloud app
- Device platform
- Location
- Sign-in risk (Identity Protection)
- User risk
- Device compliance
- Authentication strength
Decisions
- Block
- Require MFA
- Require compliant device
- Require Hybrid AAD-joined device
- Require approved client app
- Require app protection policy
- Require terms of use
Standard policy set
- Block legacy authentication
- Require MFA for all users
- Require MFA for admin roles (separate, stricter policy)
- Block sign-in from non-allowed countries
- Require compliant device for sensitive apps
- Phishing-resistant MFA for high-privilege roles
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.