What a Conditional Access policy applies to: apps in the cloud, actions users take, authentication contexts, or traffic profiles in Global Secure Access.
Also called formerly cloud apps or actions.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Target resources in context, with comparison tables and the common traps.
Terms in this definition
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
- Global Secure Access
Brand covering Microsoft's SSE (Security Service Edge) products, namely Internet Access and Private Access from Entra, which are set up through the Microsoft Entra admin center.
Related terms
- Alert rule
Azure Monitor definition made up of a scope naming the target resources, a condition setting the signal and logic, and optionally action groups. A separate rule is needed for every signal that has different recipients.