Most Microsoft 365 breaches start with an identity: a phished password, a reused credential or an old protocol that bypasses MFA. Conditional Access policies are your main control point to stop them.
This checklist covers 12 baseline policies we deploy in most tenants, and how to roll them out without locking anyone out.
Most Microsoft 365 breaches start with an identity: a phished password, a reused credential or an old protocol that bypasses MFA.
What is Conditional Access?
Conditional Access is the Zero Trust policy engine in Microsoft Entra ID. Each policy works like an if-then statement:
- If a user or group, accessing a cloud app, from certain conditions (location, device platform, client app, sign-in risk)
- Then grant access, block access, or grant with controls (MFA, compliant device, terms of use, session limits)
It is central to Zero Trust in Microsoft 365.
What do you need before you start?
- Licensing: Entra ID P1 (in Microsoft 365 Business Premium, E3, E5). Risk-based policies need P2.
- Two break-glass accounts: cloud-only, excluded from all policies, protected with strong credentials and monitored for any sign-in.
- Named locations defined for trusted offices if you plan to use them.
- Security defaults turned off once Conditional Access policies replace them.
12 baseline Conditional Access policies
| # | Policy | Target | Control |
|---|---|---|---|
| 1 | Require MFA for all users | All users, all apps | Require MFA |
| 2 | Require phishing-resistant MFA for admins | Directory roles | Authentication strength |
| 3 | Block legacy authentication | All users | Block legacy client apps |
| 4 | Require MFA for Azure and admin portals | Azure management, admin portals | Require MFA |
| 5 | Require compliant or hybrid-joined device for sensitive apps | Finance, HR, admin apps | Require device compliance |
| 6 | Require app protection on mobile | iOS and Android | Require app protection policy |
| 7 | Block access from unsupported countries | All users | Block by location |
| 8 | Require MFA for high sign-in risk (P2) | All users | MFA plus risk policy |
| 9 | Require password change for high user risk (P2) | All users | Secure password change |
| 10 | Secure security info registration | All users | Require trusted location or MFA |
| 11 | Sign-in frequency for unmanaged devices | Browser sessions | Session controls |
| 12 | Require MFA for guests | Guest users | Require MFA |
Microsoft also publishes Conditional Access templates in the Entra admin centre, grouped into categories such as Secure foundation, Zero Trust, Remote work and Protect administrator, and many of them match these baselines. Each template is created in report-only mode.
How do you roll out Conditional Access safely?
Conditional Access report-only mode insights
Illustration in progress
- Create each policy in report-only mode.
- Review sign-in logs and the Conditional Access insights workbook for one to two weeks to see who would be affected.
- Pilot with IT staff, then a small business group.
- Communicate what will change and how to register MFA.
- Enforce in waves, monitoring help-desk tickets.
- Document every policy: purpose, scope, exclusions and owner.
What are the most common Conditional Access mistakes?
- No break-glass accounts, or break-glass accounts that are not monitored
- Too many exclusions that quietly grow over time
- Overlapping policies that are hard to troubleshoot
- Relying on trusted IP locations instead of device compliance
- Forgetting service accounts and workload identities
How do you maintain Conditional Access over time?
Review policies quarterly. Check exclusion groups, look for users repeatedly blocked, and test policies with the What If tool when changing them. Use consistent naming, for example CA01-AllUsers-RequireMFA, so anyone can understand the policy set at a glance.
How Crozaint approaches Conditional Access
Identity hardening with Entra ID is one of the first workstreams in Crozaint's Microsoft 365 security deployment phase. Our 2–4 week assessment reviews your current policies, exclusions, licences and sign-in data, and the deployment phase rolls out baselines in report-only mode, then in waves.
Our focus is enforced controls rather than policies on paper. As MUJI Europe's Chath Weerasinghe put it, conditional access, device compliance and data-loss controls became enforced controls rather than documented policy. After deployment, you choose: Crozaint-managed operations or full handover to your team, and both models are reversible.
Conclusion
Twelve well-designed policies, rolled out carefully, block the majority of identity attacks against Microsoft 365. Test in report-only, protect break-glass accounts and review every quarter.
Unsure what your Conditional Access policies actually enforce? Book a 30-minute discovery call with Crozaint.

