Conditional Access is where most of your Microsoft Entra ID security actually lives. If you're starting from nothing, these five policies give you a strong baseline. They're also a core part of the SC-300 exam.
Before you start
- Create two break-glass accounts and exclude them from every policy.
- Turn each policy on in Report-only mode first and watch the sign-in logs for a week.
- Conditional Access needs Microsoft Entra ID P1. The risk-based policy below needs P2.
1. Require MFA for administrators
Target the privileged directory roles (Global Administrator, Privileged Role Administrator, Security Administrator and so on). Admin accounts are the first thing attackers go after.
2. Block legacy authentication
Older protocols such as POP, IMAP and basic SMTP authentication can't do MFA, so they're a favourite route for password-spray attacks. Block the "Other clients" and Exchange ActiveSync client apps.
3. Require MFA for all users
Once legacy authentication is blocked, require MFA for everyone. Prefer phishing-resistant methods (passkeys, Windows Hello for Business) using authentication strengths where you can.
4. Require MFA for Azure management
Target the Windows Azure Service Management API so the portal, Azure CLI and PowerShell all require MFA, even for users who aren't admins in Entra ID.
5. Respond to risky sign-ins (P2)
With Microsoft Entra ID Protection, require MFA when sign-in risk is medium or high, and require a secure password change when user risk is high.
Name your policies consistently, for example CA001-Admins-RequireMFA. Six months from now, when there are 30 of them, you'll be glad you did.
Next steps
From here, add device-based controls (require a compliant or hybrid-joined device) and session controls for unmanaged devices. My upcoming SC-300 course walks through all of this in a live tenant, and I can help roll it out through identity and security consulting.