FREE STUDY NOTES · AB-900

Conditional Access policies: signals, decisions and enforcement

How Conditional Access turns sign-in signals into block or grant decisions, and what licence it needs.

From Ultra Transcenders AB-900 by Tony Rough (coming November 2026)

Conditional Access applies the right controls only when they are needed, so users stay productive and the organisation stays protected. Microsoft calls it its Zero Trust policy engine.

Conditional Access policies are if-then statements: if a user wants to access a resource, then they must complete an action. A policy has assignments (who, what and under which conditions) and access controls (what happens). It is in the Microsoft Entra admin center under Entra ID > Conditional Access, where anyone with at least the Security Reader role can view policies. Figure 4.1 traces a sign-in from signals to decision.

Signals (who, target resource, location, device and client app, sign-in and user risk) feed Conditional Access, which is evaluated after first-factor authentication and requires every applicable policy to be satisfied. The result is either Block or Grant with requirements such as MFA or a compliant device, leading to access shaped by session controls. A dashed side path shows report-only mode, which logs results in the sign-in log without prompting or blocking.
Figure 4.1: Conditional Access takes signals, then blocks or grants with requirements; report-only mode evaluates without enforcing
Part Examples
Signals (assignments and conditions) Users, groups and agents (preview); target resources such as Microsoft 365 apps; IP locations and countries; device platform and filters for devices; client apps; sign-in risk and user risk from ID Protection
Block Most restrictive decision: access denied
Grant with requirements Require MFA, authentication strength, compliant device, Microsoft Entra hybrid joined device, approved client app, app protection policy, password change or terms of use
Session controls Shape the session after access is granted, for example sign-in frequency

How policies combine

Licences

Conditional Access needs Microsoft Entra ID P1 (also included in Microsoft 365 Business Premium). Sign-in risk and user risk conditions need ID Protection, a P2 feature. If licences expire, policies aren’t disabled or deleted; they can be viewed and deleted but not updated.

Common trap: Expecting the most permissive Conditional Access policy to win when several apply - there is no priority order; every applicable policy must be satisfied and a single block stops the sign-in.

Get the whole book

This note is one section of Ultra Transcenders AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · AB-900 terms in the glossary · All AB-900 study notes

More AB-900 study notes