MICROSOFT 365 · SECURITY

What should Conditional Access really achieve in Microsoft 365?

Conditional Access is more than enabling MFA. Effective policies consider identities, risk, devices, privileged roles, protocols and documented exceptions.

riatech GmbHIT · Software · Technology
For many businesses Microsoft 365 is the central identity and communications platform. Access controls should therefore go beyond passwords.
01

Start with a clear baseline

Define a small, understandable security baseline before creating many individual policies.

  • MFA for users and administrators
  • block legacy authentication
  • special handling for privileged roles
  • planned emergency access
02

Use device and location context carefully

Managed devices and known contexts can be treated differently from unknown clients or risky sign-ins.

  • consider device state
  • differentiate by risk
  • minimize exceptions
  • do not blindly trust locations
03

Exceptions are part of the architecture

Service accounts and special applications often require exceptions. They should be documented, justified and reviewed.

  • assign an owner
  • document technical necessity
  • define review dates
  • consider compensating controls
04

Policies should be testable and auditable

Purpose, scope and effect should be documented so technical controls can be reviewed and evidenced.

  • document policy purpose and scope
  • use report-only before enforcement
  • review sign-in logs
  • retain evidence for important controls