How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
From Ultra Transcenders SC-900 by Tony Rough (publishing soon)
Conditional Access lets an organisation apply the right access controls only when they are needed, so users stay productive and the organisation’s assets stay protected. Microsoft describes it as its Zero Trust policy engine: it brings together signals from many sources, makes a decision and enforces the organisation’s policy.
At its simplest, a Conditional Access policy is an if-then statement: if a user wants to access a resource, then they must complete an action. For example, if a user wants to access Microsoft 365, then they must perform multifactor authentication (MFA). Each policy has two parts:
A policy needs at least a name, users or groups, target resources and a grant or block control before it can be enforced.
Conditional Access policies are enforced only after first-factor authentication has completed. It is therefore not designed to be an organisation’s front-line defence against attacks such as denial of service (flooding a service with traffic to knock it over), although it can use signals from such events in its decisions. The same timing explains why an authentication strength can’t stop a user typing a password first: the policy is evaluated after that initial step. Figure 4.1 shows where Conditional Access sits in a sign-in.
Conditional Access requires Microsoft Entra ID P1 (also included in Microsoft 365 Business Premium). Policies based on sign-in risk or user risk need Microsoft Entra ID Protection, which is a P2 feature. If the licences lapse, existing policies are not disabled or deleted; they can be viewed and deleted but not updated. Tenants without P1 can use the free security defaults instead (Chapter 3: Authentication: methods, MFA and passwords).
Common trap: Relying on Conditional Access to stop a denial-of-service attack or to block the password prompt itself - policies are evaluated only after the first factor is complete; they decide what happens next, not whether the first sign-in step occurs.
This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · SC-900 terms in the glossary · All SC-900 study notes
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
What the free posture management tier includes and what the paid Defender CSPM plan adds.
What security information and event management and security orchestration, automation and response each do, and how they fit together.
The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.
The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.