azureblog.co.uk
← cd ~/learn
// learning path · beginner to intermediate

Conditional Access from zero

Build a Conditional Access setup you can trust: safe testing, emergency access, the right MFA, locations and device compliance.

0 of 7 read · about 14 minutes in total
start with part 1 →
  1. 01Break-glass accounts done rightEmergency access accounts are the one thing you hope never to use and must never get wrong. A practical checklist for setting them up and keeping them safe.2 min✓ read
  2. 02Test Conditional Access safely with report-only mode and What IfMost Conditional Access outages come from a policy that did something nobody expected. Two built-in tools let you see exactly what a policy would do before it does it.2 min✓ read
  3. 03Authentication strengths: requiring the right kind of MFARequiring MFA treats an SMS code and a passkey as equals. Authentication strengths let you say which methods are good enough for which resources.2 min✓ read
  4. 04Named locations: getting IP ranges and countries right in Conditional AccessNamed locations look simple, but trusted IPs and country blocks are easy to get subtly wrong. What they can and can't do, and how to use them well.2 min✓ read
  5. 05Rolling out "require compliant device" without a flood of ticketsRequiring a compliant device is one of the strongest Conditional Access controls you can apply. It's also one of the easiest to get wrong. A step-by-step rollout.2 min✓ read
  6. 06Require phishing-resistant MFA on every PIM activationPIM can now require a Conditional Access authentication context every time someone activates a role, and it's generally available. Here's how to set it up properly.2 min✓ read
  7. 07Six KQL queries for Entra sign-in logs every admin should keepOnce sign-in logs flow into Log Analytics, a few queries answer most of the questions you'll get. Copy these into a workbook or saved searches.2 min✓ read

Progress is saved in this browser only. A post counts as read once you've scrolled most of the way through it.