0%

Preparing the page

Conditional Access Policies: 12 Must-Have Baselines for Microsoft Entra ID

A checklist of 12 essential Microsoft Entra Conditional Access policies, from MFA and legacy auth blocking to device compliance, plus safe rollout steps.

Joseph

Joseph · Cloud Consulting

· Updated · 4 min read

Share
Placeholder illustration

Most Microsoft 365 breaches start with an identity: a phished password, a reused credential or an old protocol that bypasses MFA. Conditional Access policies are your main control point to stop them.

This checklist covers 12 baseline policies we deploy in most tenants, and how to roll them out without locking anyone out.

Most Microsoft 365 breaches start with an identity: a phished password, a reused credential or an old protocol that bypasses MFA.

What is Conditional Access?

Conditional Access is the Zero Trust policy engine in Microsoft Entra ID. Each policy works like an if-then statement:

  • If a user or group, accessing a cloud app, from certain conditions (location, device platform, client app, sign-in risk)
  • Then grant access, block access, or grant with controls (MFA, compliant device, terms of use, session limits)

It is central to Zero Trust in Microsoft 365.

What do you need before you start?

  • Licensing: Entra ID P1 (in Microsoft 365 Business Premium, E3, E5). Risk-based policies need P2.
  • Two break-glass accounts: cloud-only, excluded from all policies, protected with strong credentials and monitored for any sign-in.
  • Named locations defined for trusted offices if you plan to use them.
  • Security defaults turned off once Conditional Access policies replace them.

12 baseline Conditional Access policies

#PolicyTargetControl
1Require MFA for all usersAll users, all appsRequire MFA
2Require phishing-resistant MFA for adminsDirectory rolesAuthentication strength
3Block legacy authenticationAll usersBlock legacy client apps
4Require MFA for Azure and admin portalsAzure management, admin portalsRequire MFA
5Require compliant or hybrid-joined device for sensitive appsFinance, HR, admin appsRequire device compliance
6Require app protection on mobileiOS and AndroidRequire app protection policy
7Block access from unsupported countriesAll usersBlock by location
8Require MFA for high sign-in risk (P2)All usersMFA plus risk policy
9Require password change for high user risk (P2)All usersSecure password change
10Secure security info registrationAll usersRequire trusted location or MFA
11Sign-in frequency for unmanaged devicesBrowser sessionsSession controls
12Require MFA for guestsGuest usersRequire MFA

Microsoft also publishes Conditional Access templates in the Entra admin centre, grouped into categories such as Secure foundation, Zero Trust, Remote work and Protect administrator, and many of them match these baselines. Each template is created in report-only mode.

How do you roll out Conditional Access safely?

Report-only results
  1. Create each policy in report-only mode.
  2. Review sign-in logs and the Conditional Access insights workbook for one to two weeks to see who would be affected.
  3. Pilot with IT staff, then a small business group.
  4. Communicate what will change and how to register MFA.
  5. Enforce in waves, monitoring help-desk tickets.
  6. Document every policy: purpose, scope, exclusions and owner.

What are the most common Conditional Access mistakes?

  • No break-glass accounts, or break-glass accounts that are not monitored
  • Too many exclusions that quietly grow over time
  • Overlapping policies that are hard to troubleshoot
  • Relying on trusted IP locations instead of device compliance
  • Forgetting service accounts and workload identities

How do you maintain Conditional Access over time?

Review policies quarterly. Check exclusion groups, look for users repeatedly blocked, and test policies with the What If tool when changing them. Use consistent naming, for example CA01-AllUsers-RequireMFA, so anyone can understand the policy set at a glance.

How Crozaint approaches Conditional Access

Identity hardening with Entra ID is one of the first workstreams in Crozaint's Microsoft 365 security deployment phase. Our 2–4 week assessment reviews your current policies, exclusions, licences and sign-in data, and the deployment phase rolls out baselines in report-only mode, then in waves.

Our focus is enforced controls rather than policies on paper. As MUJI Europe's Chath Weerasinghe put it, conditional access, device compliance and data-loss controls became enforced controls rather than documented policy. After deployment, you choose: Crozaint-managed operations or full handover to your team, and both models are reversible.

Conclusion

Twelve well-designed policies, rolled out carefully, block the majority of identity attacks against Microsoft 365. Test in report-only, protect break-glass accounts and review every quarter.

Unsure what your Conditional Access policies actually enforce? Book a 30-minute discovery call with Crozaint.

Frequently Asked Questions

What is a Conditional Access policy?

A Conditional Access policy is a rule in Microsoft Entra ID that evaluates sign-in signals such as user, app, device, location and risk, then allows access, blocks it or requires additional controls like MFA or a compliant device. It is the core of Zero Trust identity security in Microsoft 365.

Does Conditional Access require a premium licence?

Yes. Conditional Access requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium, E3 and E5. Risk-based Conditional Access, using sign-in and user risk from Entra ID Protection, requires Entra ID P2, included in Microsoft 365 E5.

What is report-only mode?

Report-only mode lets you evaluate a Conditional Access policy without enforcing it. Entra ID logs what would have happened for each sign-in, so you can see who would be affected before turning the policy on. It is the safest way to introduce new policies.

Why should we block legacy authentication?

Legacy authentication protocols such as basic authentication for older mail clients cannot perform MFA. Attackers use them for password spraying because they bypass MFA. Blocking legacy authentication closes a common attack path with very little impact on modern clients.

What is a break-glass account?

A break-glass account is an emergency administrator account excluded from Conditional Access policies, used only if normal admin access is lost, for example after a policy misconfiguration or an MFA outage. It should be cloud-only, strongly protected and monitored with alerts on every sign-in.

Joseph

Written by

Joseph

Cloud Consulting · 15 articles

Joseph has spent fifteen years at the operating end of infrastructure — from data-centre and network operations to multi-cloud consulting across AWS, Azure and GCP. He turns unreadable cloud bills into decisions teams can act on, and he knows the automation underneath them — Terraform, Ansible, Kubernetes — well enough to make the savings stick.

Nidhish JoyReviewed for technical accuracy by Nidhish Joy, Co-founder & CEO.

After the reading

Reading About Digital Workplace & Security Is the Easy Part.Doing It in Your Estate Is Ours.

Thirty minutes with the people who wrote this. We look at your setup, say what we would fix first and leave you with a plan, whether or not you go further with us.

  • A look at your estate, not a demo
  • What we would fix first, and why
  • A plan you keep, whether or not you hire us
Joseph

Talk to Joseph

Wrote this article · Cloud Consulting

Thirty minutes on your estate. Joseph looks at what you have and tells you what we would do first.

Book 30 Minutes

No deck, no pitch, no commitment.