Identity & security

Five Conditional Access policies every Entra ID tenant should have

A practical baseline for Microsoft Entra Conditional Access, and the order to roll it out in.

By Vikas Garg · 6 min read

Conditional Access is where most of your Microsoft Entra ID security actually lives. If you're starting from nothing, these five policies give you a strong baseline. They're also a core part of the SC-300 exam.

Before you start

1. Require MFA for administrators

Target the privileged directory roles (Global Administrator, Privileged Role Administrator, Security Administrator and so on). Admin accounts are the first thing attackers go after.

2. Block legacy authentication

Older protocols such as POP, IMAP and basic SMTP authentication can't do MFA, so they're a favourite route for password-spray attacks. Block the "Other clients" and Exchange ActiveSync client apps.

3. Require MFA for all users

Once legacy authentication is blocked, require MFA for everyone. Prefer phishing-resistant methods (passkeys, Windows Hello for Business) using authentication strengths where you can.

4. Require MFA for Azure management

Target the Windows Azure Service Management API so the portal, Azure CLI and PowerShell all require MFA, even for users who aren't admins in Entra ID.

5. Respond to risky sign-ins (P2)

With Microsoft Entra ID Protection, require MFA when sign-in risk is medium or high, and require a secure password change when user risk is high.

Name your policies consistently, for example CA001-Admins-RequireMFA. Six months from now, when there are 30 of them, you'll be glad you did.

Next steps

From here, add device-based controls (require a compliant or hybrid-joined device) and session controls for unmanaged devices. My upcoming SC-300 course walks through all of this in a live tenant, and I can help roll it out through identity and security consulting.