← cd ~/learn
// learning path · beginner to intermediate
Conditional Access from zero
Build a Conditional Access setup you can trust: safe testing, emergency access, the right MFA, locations and device compliance.
0 of 7 read · about 14 minutes in total
- 01Break-glass accounts done rightEmergency access accounts are the one thing you hope never to use and must never get wrong. A practical checklist for setting them up and keeping them safe.2 min✓ read
- 02Test Conditional Access safely with report-only mode and What IfMost Conditional Access outages come from a policy that did something nobody expected. Two built-in tools let you see exactly what a policy would do before it does it.2 min✓ read
- 03Authentication strengths: requiring the right kind of MFARequiring MFA treats an SMS code and a passkey as equals. Authentication strengths let you say which methods are good enough for which resources.2 min✓ read
- 04Named locations: getting IP ranges and countries right in Conditional AccessNamed locations look simple, but trusted IPs and country blocks are easy to get subtly wrong. What they can and can't do, and how to use them well.2 min✓ read
- 05Rolling out "require compliant device" without a flood of ticketsRequiring a compliant device is one of the strongest Conditional Access controls you can apply. It's also one of the easiest to get wrong. A step-by-step rollout.2 min✓ read
- 06Require phishing-resistant MFA on every PIM activationPIM can now require a Conditional Access authentication context every time someone activates a role, and it's generally available. Here's how to set it up properly.2 min✓ read
- 07Six KQL queries for Entra sign-in logs every admin should keepOnce sign-in logs flow into Log Analytics, a few queries answer most of the questions you'll get. Copy these into a workbook or saved searches.2 min✓ read
Progress is saved in this browser only. A post counts as read once you've scrolled most of the way through it.