Grant control in Conditional Access that restricts which combinations of methods meet a policy, for example the built-in Phishing-resistant MFA. It narrows methods without enabling them; enabling is done in the authentication methods policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Authentication strength in context, with comparison tables and the common traps.
Terms in this definition
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Phishing-resistant MFA
Authentication that is tied to the real website and the user's device, so a fake site cannot capture and replay it. Examples include passkeys (FIDO2), Windows Hello for Business and certificate-based authentication used as multifactor; Conditional Access can demand these through a built-in authentication strength.
- Authentication methods policy
Tenant-level Microsoft Entra policy that switches on each sign-in method, such as FIDO2, Authenticator, certificate-based authentication, TAP or SMS, for chosen users or groups.
Related terms
- Require risk remediation
Leaves it to ID Protection to decide how a risky user is fixed, either reauthentication or a secure password change, regardless of how they sign in. Selecting it also adds sign-in frequency set to Every time and an authentication strength.