Security

Entra ID Conditional Access: a starter policy set

09 Jul 2026 · 1 min read

Conditional Access is the single highest-leverage control in a Microsoft tenant, and it's usually either wide open or so tight that people can't work. Here's a middle path we deploy on most engagements.

Run it in report-only first

Every policy below goes in as report-only for a week. You get the sign-in impact in the logs without locking anyone out, and you fix the surprises before enforcement.

The six policies

  1. Require MFA for all users.
  2. Block legacy authentication.
  3. Require compliant or hybrid-joined devices for desktop apps.
  4. Require MFA for risky sign-ins.
  5. Require password change for risky users.
  6. Block access from unsupported countries.

What to watch

The device policy (3) is the one that generates tickets if Intune enrolment isn't finished. Sequence it last, after enrolment is above ~95%.

Have a process like this one?

Tell us the steps. We'll tell you what automating them looks like.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin. Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session. Please retry or reload the page.