Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AZ-900SC-900AB-900SC-200SC-300MD-102ALZ
Each book explains Conditional Access in context, with comparison tables and the common traps.
Terms in this definition
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Microsoft Entra ID P1
Premium tier of Microsoft Entra ID, bundled with Microsoft 365 Business Premium, that unlocks capabilities like Conditional Access.
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- Named locations
Countries or IP address ranges you define in Microsoft Entra ID so that Conditional Access policies can use them as conditions.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
Related terms
- Adaptive Protection
A Microsoft Purview capability in which Insider Risk Management rates each person as Minor, Moderate or Elevated risk. DLP, Conditional Access and data lifecycle policies then adjust automatically, so the tightest restrictions fall on the highest-risk people only.
- Agent identity
Service principal of a special kind representing an AI agent, holding no credentials itself. It can act on its own using app-only permissions or for a user using delegated ones; Conditional Access offers only block, not grant controls, for it.
- Agent identity blueprint
Template in Microsoft Entra Agent ID that holds credentials for one type of agent and obtains tokens for the agent identities created from it. Policies like Conditional Access set on it reach all those identities; Azure RBAC roles cannot be assigned to it.
- Agent risk
Condition in Conditional Access based on the risk level Microsoft Entra ID Protection assigns to agent identities, letting a policy stop high-risk agents from obtaining tokens.
- All resources (Conditional Access)
Broadest Conditional Access target, previously called All cloud apps, which takes in every resource such as Microsoft 365 and the Azure portal. Microsoft Azure Management covers less.
- Application-enforced restrictions
Lets Exchange Online or SharePoint Online learn whether a device is managed and compliant: on such devices users get everything, while elsewhere they get a cut-down experience such as browser-only access. It is a Conditional Access session control.
- Authentication context
A Conditional Access tag placed on just one sensitive area or action within an app (a particular SharePoint site, say, or activating a PIM role), so tougher sign-in conditions apply there without covering everything else in the app.
- Authentication strength
Grant control in Conditional Access that restricts which combinations of methods meet a policy, for example the built-in Phishing-resistant MFA. It narrows methods without enabling them; enabling is done in the authentication methods policy.