Sensitive Microsoft Entra operations, such as permanent deletion or changes to Conditional Access, tied to an authentication context so Conditional Access is checked at the moment the action happens instead of at sign-in. It needs P1.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Protected actions in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Authentication context
A Conditional Access tag placed on just one sensitive area or action within an app (a particular SharePoint site, say, or activating a PIM role), so tougher sign-in conditions apply there without covering everything else in the app.