Using sign-in data sent to a Log Analytics workspace, this workbook estimates what all your Conditional Access policies, report-only ones included, would do together over a chosen window between 4 hours and 90 days. It needs an Entra ID P1 licence and a role of Security Reader or above.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Conditional Access insights and reporting in context, with comparison tables and the common traps.
Terms in this definition
- Log Analytics workspace
Where Azure Monitor keeps log data for querying with KQL. Microsoft Sentinel, VM insights and workspace-based Application Insights all depend on one.
- Workbook
An interactive report in Azure Monitor that brings together text, metrics and logs.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Report-only
Conditional Access state in which a policy is evaluated and its outcome logged, but not enforced.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- WINDOW
Returns rows from a sorted, optionally partitioned table, either at fixed positions (ABS) or relative to the current row (REL). Running totals plus moving averages are common uses.
- Entra ID P1
Conditional Access requires this Entra licence, as does protecting on-premises AD with Password Protection.
See Conditional Access insights and reporting in the full glossary