Microsoft Entra Security Insight
Conditional Access Explained: What Is It and Why Should You Use It?
Learn how Microsoft Entra Conditional Access works, which signals and controls it uses, licensing requirements and how to deploy policies safely.
Conditional Access applies the right security requirement at the point of access. It can require MFA, a compliant device or another control based on the user, application, device, location and risk context.
What Is Microsoft Entra Conditional Access?
Microsoft Entra Conditional Access is Microsoft's Zero Trust policy engine. It evaluates identity-driven signals and applies access controls when users or workloads try to reach applications and resources.
A simple policy follows an if-then model: if a user attempts to access a resource under defined conditions, then require a control such as MFA, a compliant device or a specific authentication strength.
Which Signals Can Conditional Access Use?
- User and group membership.
- Cloud application or action being accessed.
- Device platform and compliance state.
- Network location and named locations.
- Client application and legacy authentication protocol.
- User risk and sign-in risk where eligible licensing is available.
- Authentication context and selected workload identities.
What Can a Conditional Access Policy Do?
| Decision | Examples |
|---|---|
| Block access | Prevent access when defined assignments and conditions apply. |
| Grant with requirements | Require MFA, authentication strength, compliant device, hybrid join, approved app or app protection policy. |
| Control the session | Apply sign-in frequency, persistent-browser settings or supported app-session restrictions. |
Common Conditional Access Policies
- Require MFA for administrative roles.
- Require MFA for users accessing Microsoft 365.
- Block legacy authentication.
- Require compliant devices for sensitive applications.
- Protect security-information registration.
- Control access by location or device platform.
- Apply risk-based controls where Microsoft Entra ID P2 is licensed.
Conditional Access Licensing
Conditional Access is available with Microsoft Entra ID Premium P1 and is included in Microsoft 365 Business Premium. Risk-based user and sign-in policies require Microsoft Entra ID Protection capabilities associated with Entra ID P2. Other integrated controls may require Intune, Defender for Cloud Apps or additional licensing.
How to Deploy Conditional Access Safely
1. Inventory access
Identify users, administrators, guests, service accounts, applications, devices and legacy protocols.
2. Protect emergency access
Maintain tightly controlled emergency access accounts excluded from normal policies, with monitoring and documented use.
3. Build a baseline
Create a small set of clearly named policies rather than one overly complex policy.
4. Start in report-only mode
Evaluate expected policy impact without enforcing the result.
5. Use pilot groups
Include representative users, devices and business applications before broad rollout.
6. Validate with tools and logs
Use the What If tool and sign-in logs to understand which policies apply and why.
7. Enforce in stages
Expand gradually, monitor support demand and retain rollback instructions.
Conditional Access Design Principles
Common Conditional Access Mistakes
- Enabling a block policy tenant-wide without report-only testing.
- Failing to exclude and secure emergency access accounts.
- Leaving administrator roles under-protected.
- Creating overlapping policies with unclear outcomes.
- Using trusted locations as the sole security control.
- Ignoring service accounts and legacy applications.
- Never reviewing old exclusions.
Official Microsoft References
Frequently Asked Questions
What is Conditional Access?
Conditional Access is Microsoft's policy engine for making access decisions using signals such as user, device, application, location and risk.
Does Microsoft 365 Business Premium include Conditional Access?
Yes. Microsoft 365 Business Premium includes Microsoft Entra ID Premium P1 capabilities, including Conditional Access.
Is Conditional Access the same as MFA?
No. MFA is one possible grant requirement. Conditional Access decides when MFA or another control should be required.
Can Conditional Access lock everyone out?
Poorly designed policies can cause widespread access problems. Use report-only mode, pilot groups, the What If tool and protected emergency access accounts.
Need Help with Conditional Access?
Fedelta helps Australian businesses design, test and deploy Conditional Access policies without losing sight of business continuity, support and user experience.
Book a consultation