Module 6 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: how Conditional Access turns sign-in signals into access decisions, the anatomy of a policy, the three baseline policies every business needs, and the report-only rollout discipline that keeps you from locking yourself out.
Conditional Access, Done Properly
If MFA is the lock, Conditional Access is the doorman
Back in Module 1 you switched on MFA, and that was the big win. But MFA on its own is a lock that treats every knock at the door exactly the same. Your accountant signing in from the office at 9am gets the same challenge as someone trying an old mail protocol from the other side of the world at 3am.
Conditional Access is Microsoft's policy engine for fixing that. At its simplest, every policy is an if-then statement: if a sign-in matches the conditions you describe, then apply the controls you chose. It gathers signals about each sign-in, weighs them against your policies, and makes a decision on the spot.
Who is signing in
User, group, or role
Where from
Network or country
What device
Platform and state
What they want
The app or resource
How risky it looks
Sign-in and user risk
Your Conditional Access policies
If the sign-in matches this... then do that.
Block
No entry, full stop
Grant, with conditions
MFA, compliant device, and so on
If MFA is the lock on the door, Conditional Access is the doorman standing next to it. The lock asks one question of everyone. The doorman sizes up who you are, where you came from, and what you are carrying, then decides whether you walk straight in, show extra ID, or head back to the taxi rank.
Two housekeeping notes before we go deeper. Conditional Access needs Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium and E3 (risk signals from Entra ID Protection need P2, which comes with E5). And policies are enforced after the first factor is completed, so it is a second gate behind the password, not a replacement for it.