Module 6 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: how Conditional Access turns sign-in signals into access decisions, the anatomy of a policy, the three baseline policies every business needs, and the report-only rollout discipline that keeps you from locking yourself out.

    Conditional Access, Done Properly

    Module 6 · DevicesUnit 1 of 6 · about 2 min

    If MFA is the lock, Conditional Access is the doorman

    Back in Module 1 you switched on MFA, and that was the big win. But MFA on its own is a lock that treats every knock at the door exactly the same. Your accountant signing in from the office at 9am gets the same challenge as someone trying an old mail protocol from the other side of the world at 3am.

    Conditional Access is Microsoft's policy engine for fixing that. At its simplest, every policy is an if-then statement: if a sign-in matches the conditions you describe, then apply the controls you chose. It gathers signals about each sign-in, weighs them against your policies, and makes a decision on the spot.

    Signals in, decision out

    Who is signing in

    User, group, or role

    Where from

    Network or country

    What device

    Platform and state

    What they want

    The app or resource

    How risky it looks

    Sign-in and user risk

    Your Conditional Access policies

    If the sign-in matches this... then do that.

    Block

    No entry, full stop

    Grant, with conditions

    MFA, compliant device, and so on

    The doorman way to think about it

    If MFA is the lock on the door, Conditional Access is the doorman standing next to it. The lock asks one question of everyone. The doorman sizes up who you are, where you came from, and what you are carrying, then decides whether you walk straight in, show extra ID, or head back to the taxi rank.

    Two housekeeping notes before we go deeper. Conditional Access needs Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium and E3 (risk signals from Entra ID Protection need P2, which comes with E5). And policies are enforced after the first factor is completed, so it is a second gate behind the password, not a replacement for it.

    StartCloud Assistant

    Online

    G'day! 👋 I'm the StartCloud Assistant. How can I help you today?