The part of a Conditional Access policy that either blocks access or demands conditions such as MFA, a compliant device or an approved client app. Several can be combined, requiring all of them or just one.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Grant controls in context, with comparison tables and the common traps.
Terms in this definition
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Agent demands
Exists or equals conditions in a pipeline's pool that Pipelines checks against self-hosted agents' capabilities to choose one. With Microsoft-hosted agents, an image is selected instead.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
Related terms
- Agent identity
Service principal of a special kind representing an AI agent, holding no credentials itself. It can act on its own using app-only permissions or for a user using delegated ones; Conditional Access offers only block, not grant controls, for it.
- Microsoft Intune
Microsoft's endpoint management service, run from the cloud, covering both MDM and MAM. Conditional Access grant controls can depend on its compliance policies for devices and protection policies for apps.