How a Conditional Access policy is built and how multiple policies combine.
From Ultra Transcenders SC-500 by Tony Rough (publishing soon)
Conditional Access is the Microsoft Entra policy engine that evaluates each sign-in against assignments and conditions and then grants, blocks or restricts the session. Each part of a policy has a specific job, and many wrong answers put a control in the wrong part. Figure 1.2 shows how the parts fit together.
| Policy part | Holds | Examples |
|---|---|---|
| Users / agents | Who is in scope, with exclusions | Users, groups, directory roles, agent identities |
| Target resources (Cloud apps or actions) | Which app | All resources, Windows Azure Service Management API (formerly Microsoft Azure Management) |
| Conditions | When it applies | Device platform, locations, sign-in/user/agent risk |
| Grant controls | Block, or require controls | MFA, compliant device, approved client app, app protection policy |
| Session controls | Session lifetime and restrictions | Sign-in frequency, app-enforced restrictions |
Common trap: Configuring the compliant-device requirement under Conditions - it’s a grant control; Conditions only decide when the policy applies (device platform, location, risk).
This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free SC-500 glossary · All SC-500 study notes
How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.
Why control-plane roles can't read secrets, and which Key Vault role or access policy each task needs.
What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.
Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.
Where each Azure SQL data protection feature works and who it protects data from.
How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow.
How JIT locks management ports and opens them on request, with the plan and permissions it needs.