azureblog.co.uk
← cd ~/learn
azureblog.co.uk · cheat sheet

Conditional Access building blocks

What goes into a Conditional Access policy, how policies combine, and the baseline set most tenants should have.

Fits on one A4 page. Checked 8 Oct 2026.

Assignments: who and what

  • Users: all users, users and groups, directory roles, guests and external users. Always exclude break-glass accounts.
  • Target resources: cloud apps, user actions (register security info, register or join devices) or an authentication context.
  • Network: include or exclude named locations, such as trusted IP ranges or countries.

Conditions: when

  • User risk and sign-in risk (Entra ID P2)
  • Device platforms: Windows, macOS, iOS, Android, Linux
  • Client apps: browser, mobile and desktop apps, Exchange ActiveSync and other legacy clients
  • Filter for devices: rules on device properties
  • Authentication flows: device code flow and authentication transfer

Grant: what's required

  • Block access
  • Require MFA or a specific authentication strength
  • Require compliant device or hybrid joined device
  • Require app protection policy
  • Require password change (with user risk)
  • Terms of use

Within one policy, choose whether all or one of the selected controls is needed.

Session: how long and how much

  • Sign-in frequency: how often users re-authenticate. "Every time" for sensitive actions.
  • Persistent browser session
  • App enforced restrictions: browser-only access in SharePoint and Exchange
  • Conditional Access App Control: session control through Defender for Cloud Apps
  • Continuous access evaluation settings

How policies combine

  • Every policy that applies to a sign-in is evaluated. There's no order or priority.
  • Block wins. If any applicable policy blocks, access is blocked.
  • Otherwise the user must satisfy the grant controls of every applicable policy.
  • Report-only policies are evaluated and logged but never enforced.
  • Exclusions beat inclusions: an excluded user isn't in scope, whatever else the policy includes.

A baseline set

PolicyUsersResourcesControl
Block legacy authenticationAllAllBlock (client apps: Exchange ActiveSync, other)
MFA for everyoneAllAllAuthentication strength: MFA
Phishing-resistant MFA for adminsAdmin rolesAllAuthentication strength: phishing-resistant
Protect security info registrationAllUser action: register security infoMFA, or a trusted location
Block device code flowAllAllBlock (authentication flows: device code)
Compliant device for corporate appsStaffAll or key appsCompliant or hybrid joined device
Risk-based (P2)AllAllHigh user risk: secure password change. High sign-in risk: MFA

Exclude break-glass accounts from every policy, and test with report-only and What If before switching on. Check your own policies with the Conditional Access visualiser.