How Conditional Access turns sign-in signals into block or grant decisions, and what licence it needs.
From Ultra Transcenders AB-900 by Tony Rough (coming November 2026)
Conditional Access applies the right controls only when they are needed, so users stay productive and the organisation stays protected. Microsoft calls it its Zero Trust policy engine.
Conditional Access policies are if-then statements: if a user wants to access a resource, then they must complete an action. A policy has assignments (who, what and under which conditions) and access controls (what happens). It is in the Microsoft Entra admin center under Entra ID > Conditional Access, where anyone with at least the Security Reader role can view policies. Figure 4.1 traces a sign-in from signals to decision.
| Part | Examples |
|---|---|
| Signals (assignments and conditions) | Users, groups and agents (preview); target resources such as Microsoft 365 apps; IP locations and countries; device platform and filters for devices; client apps; sign-in risk and user risk from ID Protection |
| Block | Most restrictive decision: access denied |
| Grant with requirements | Require MFA, authentication strength, compliant device, Microsoft Entra hybrid joined device, approved client app, app protection policy, password change or terms of use |
| Session controls | Shape the session after access is granted, for example sign-in frequency |
Conditional Access needs Microsoft Entra ID P1 (also included in Microsoft 365 Business Premium). Sign-in risk and user risk conditions need ID Protection, a P2 feature. If licences expire, policies aren’t disabled or deleted; they can be viewed and deleted but not updated.
Common trap: Expecting the most permissive Conditional Access policy to win when several apply - there is no priority order; every applicable policy must be satisfied and a single block stops the sign-in.
This note is one section of Ultra Transcenders AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AB-900 terms in the glossary · All AB-900 study notes
Verify explicitly, use least privilege access and assume breach, and the pillars they apply to.
What the score measures, how often it is recalculated and which recommendations raise it.
What each Exchange Online mailbox permission allows and which recipients and groups can hold it.
Sharing-link, permission and Everyone except external users reports for finding oversharing.
How restricted site access limits a site to members of chosen groups, even for users with permission.
What the two built-in reasoning agents are for, how they are deployed and when a custom agent fits.
How billing policies connect metered Copilot Chat and SharePoint agent use to an Azure subscription, and what budgets do.