Infrastructure / Security and Identity / Conditional Access
Writing the access rule is easy. Knowing who it applies to is much harder.
Who is entering, from where, on what device—and what they are asked to prove.Conditional access examines every connection to your Microsoft 365 services and determines what to require: multi-factor authentication, a company-managed device, or nothing at all because the person is in the office using their usual computer. The challenge is never the syntax; it’s knowing who is involved in each scenario and making sure no one gets locked out while figuring it out.
Connections That Raise Questions
A correct password doesn't mean much on its own. It just means that someone knows the password—not that it's the right person, nor that the device being used is trustworthy enough to handle your documents.
A connection is coming in from a country where no one works
The account is valid, the password is correct, and the login is coming from a location where your company has no office, no clients, and no employees on business travel.
A requirement related to the connection location may require additional verification or prevent access, and the system will notify you of this.
An employee checks his email on his personal phone
The device is not managed by the company; it may not have a passcode; and it may end up being resold with the documents still on it.
Access can remain open in the browser without allowing the download, or require a managed device to proceed.
An external service provider accesses your documents
He needs two folders for three months. His guest account often remains active long after the work is finished, and no one closes it.
Guest accounts have their own, stricter requirements, without complicating things for your internal teams.
An outdated protocol bypasses all verification
Some older email clients do not support multi-factor authentication. An account accessed this way can be accessed using only the password.
It's the first thing we shut down, and often the one that has the biggest impact on the actual level of risk.
An admin account can also be used to read emails
The same account is used to access email, browse the web, and manage the directory. A single malicious page is then enough to grant the highest privileges.
Administrator accounts have separate requirements and are used solely for administrative purposes.
Two logins from the same account, two hours apart by plane
The first one is from Lausanne at 9:00 a.m., and the second is from the other side of the world at 9:20 a.m. One of them isn't the right person.
Microsoft Entra ID Protection flags this type of connection as risky, and conditional access may then require additional identity verification.
What Conditional Access Is About, and What It Requires
A conditional access policy reads like a sentence: if a certain person, from a certain location, on a certain device, opens a certain app—then require this. The whole process involves filling in the blanks for your company.
What He's Watching
Connection signals
- Who—the person, their group, their administrative role, and whether it is a guest account.
- From where—the network address, the country, and the locations you have designated as your offices.
- On which device—whether it's managed by the company or not, and whether it meets your requirements or not.
- Which application—email, documents, ordirectory management?
- What level of risk are we talking about—an unusual login, or an account whose password has been leaked?
What he may demand
The decision, once the signals have been interpreted
- Multifactor authentication—right away, or only when you're away from your office.
- A managed and compliant device—otherwise, access is denied.
- A limited-time session—read in your browser, no download or printing required.
- Periodic reconnection—instead of a session that remains open indefinitely.
- Nothing at all—and that's usually the case for anyone who works a normal job.
The device-type-based condition is based on what the browser reports about itself: Microsoft notes that it can be spoofed. It is intended to guide usage, never to serve as a standalone security requirement.
What we're implementing first
Six points, in this order, before making any specific requests. They cover most of the actual risk and can be explained to management in five minutes.
Two emergency access accounts
Exempt from all requirements, with a long password stored outside the system, and tested before they are needed.
Legacy Closed Protocols
Authentication methods that do not support a second factor are rejected for everyone.
A second factor affecting administrative accounts
Without exception and regardless of location: these are the accounts whose losses are the most costly.
A second factor for everyone
This is addressed next, once the specific cases are known. Microsoft itself now requires this for administration.
Requirements Specific to Guest Accounts
An outside contractor is not entitled to the same terms as an employee of your company.
A predetermined session duration
Rather than a session that remains open indefinitely on a shared device or in a public place.
The only truly costly mishap: locking yourself out
A misdirected requirement may apply to all accounts, including yours. At that point, no one can log in to remove it, and recovery requires filing a request with Microsoft, with the resulting delay.
That is why emergency access accounts are set up first, separate from everything else, and why we verify that they work before implementing anything else.
How We Do It
Five steps, in this order. The third step is the one that helps you avoid unpleasant surprises: you consider what might happen before anything actually happens.
Track who is logging in and how
Active accounts, forgotten service accounts, devices in use, usual login locations, and old protocols that are still open. This report determines everything else.
Set up emergency access accounts and test them
Before the first requirement. An emergency account that has never been tested is not an emergency account.
View in report-only mode
Each request is initially made to no avail: she reads it, counts it, and reports who might be affected. That’s how we discover the service account that has apparently stopped working, or the team on the road that was turned away on a Monday morning.
Roll out in phases, starting with the IT department
Start with your technical teams, then a pilot department, and then the rest. Each phase allows for adjustments before the next one, so no one is caught off guard by the change one morning without warning.
Document and plan for the review
Each requirement is documented along with the reason it was established. Without that reason, no one dares to change it two years later, and the whole thing becomes set in stone.
What You Need to Know Before Making a Decision
Four questions that come up in every project.
What licenses are required?
Conditional access requires Microsoft Entra ID P1. Risk-based decisions regarding a sign-in or an account require P2. Both plans are available separately and as part of certain Microsoft 365 suites.
What about the default security settings—are they already enabled?
The two cannot coexist: enabling conditional access requires disabling the default security. This provides greater flexibility, but it also removes an automatic safety net—hence the importance of the initial foundation.
Is our directory already affected without us knowing it?
Probably. Microsoft itself deploys certain requirements in eligible directories—initially as drafts—and then activates them after about 30 days if no one takes action. They appear in the admin center, marked as created by Microsoft.
What Conditional Access Doesn't Do
It controls who comes in, not what goes out. Preventing a document from leaving once someone has entered falls under data loss prevention, and that's a different issue.
Further Reading
Conditional access relies on what you know about your devices and identities, and it ends where document monitoring begins.
The directory on which everything depends
Microsoft Entra ID: Identities, Groups, Roles, and the P1 and P2 plans.Knowing Whether a Device Is Compliant
Without device management, the “managed device” requirement has no one to whom it applies.Prevent a document from being sent
What Happens After Input: Sensitive Content and the Paths It Takes.Identifying a device by its certificate
Internal certificates and authentication that requires no user input.How Access Protection Can Be Bypassed
Our detailed guide, written from the perspective of someone trying to get through.Industry Terms, Explained
Second factor, compliant device, session token: the jargon-free terminology.Tell us about your access options, and we'll let you know where to start.
The initial conversation is meant to identify who is joining and where they’re connecting from, and then to determine what needs to be addressed first. You’ll meet the people who will actually do the work—not a salesperson who will just describe it.
Renens +41 21 806 37 15 · Sion +41 27 552 00 22 · Châtel-Saint-Denis +41 26 322 59 05


