Microsoft Cloud4 min read221 lines

Learning state

Track this guide

Saved in this browser only. No account required.

Conditional Access Master Class

Production-ready Microsoft Entra Conditional Access guide for safe report-only validation, break-glass protection, staged enforcement, policy templates, monitoring, and rollback.

Table of Contents


Operating Model

Conditional Access is a production access-control system. A bad policy can block administrators, service accounts, automations, mobile users, or entire departments. The safe operating model is to inventory first, stage in report-only mode, pilot with a known group, and enforce only after sign-in evidence has been reviewed.

Golden rules

  • Maintain at least two cloud-only break-glass accounts.
  • Exclude break-glass accounts intentionally and document the exclusion.
  • Start every new policy in report-only mode.
  • Never target all users and all cloud apps without a pilot window.
  • Record rollback steps before enabling enforcement.
Connect-MgGraph -Scopes "Policy.Read.All","AuditLog.Read.All","Directory.Read.All"
Get-MgIdentityConditionalAccessPolicy -All | Select-Object Id,DisplayName,State,CreatedDateTime,ModifiedDateTime
Get-MgAuditLogSignIn -Top 20 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus

Baseline Inventory

Inventory tells you what exists before you propose a new control. Capture policies, named locations, users, groups, role assignments, and recent sign-in failures.

Connect-MgGraph -Scopes "Policy.Read.All","Directory.Read.All","AuditLog.Read.All","RoleManagement.Read.Directory"
Get-MgIdentityConditionalAccessPolicy -All
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabled,UserType
Get-MgDirectoryRole -All | Select-Object Id,DisplayName
Get-MgAuditLogSignIn -Top 50

Evidence to save

  • Policy name, state, assignments, controls, and session settings.
  • Groups targeted or excluded by each policy.
  • Recent sign-ins where ConditionalAccessStatus is failure or notApplied.
  • Guest and service-account patterns.
  • Administrator role membership.

Break-Glass Protection

Break-glass accounts keep the tenant recoverable when Conditional Access, MFA, federation, device compliance, or network controls fail.

Connect-MgGraph -Scopes "User.Read.All","Policy.Read.All","AuditLog.Read.All"
Get-MgUser -Filter "startsWith(displayName,'Break Glass')" -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Get-MgIdentityConditionalAccessPolicy -All | Select-Object DisplayName,State
Get-MgAuditLogSignIn -Top 50 | Where-Object { $_.UserPrincipalName -like '*break*' }

Requirements

  • Two cloud-only accounts.
  • Long vaulted passwords.
  • No routine use.
  • Excluded from policies that can block recovery.
  • Alert on every sign-in attempt.
  • Tested recovery procedure.

Report-Only Rollout

Report-only mode is the safest way to test policy effect. Operators should review impact before enforcement.

Rollout sequence

  1. Draft policy with narrow scope.
  2. Set state to report-only.
  3. Wait through a normal business cycle.
  4. Review sign-in log impact.
  5. Pilot with a small group.
  6. Expand target group.
  7. Enable enforcement.
  8. Watch sign-in logs for failures.
Connect-MgGraph -Scopes "Policy.Read.All","AuditLog.Read.All"
Get-MgIdentityConditionalAccessPolicy -All | Where-Object { $_.State -eq 'enabledForReportingButNotEnforced' }
Get-MgAuditLogSignIn -Top 100 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus

Policy Template: Require MFA for Administrators

This should usually be the first enforced policy because privileged accounts carry the highest blast radius.

Target

  • Include directory roles for administrators.
  • Exclude break-glass accounts.
  • Require multifactor authentication.
  • Start as report-only.
Connect-MgGraph -Scopes "Policy.Read.All","RoleManagement.Read.Directory"
Get-MgDirectoryRole -All | Sort-Object DisplayName
Get-MgIdentityConditionalAccessPolicy -All | Select-Object DisplayName,State

Validation

  • Admin sign-ins show MFA required in report-only impact.
  • Break-glass accounts remain reachable.
  • Service accounts are not accidentally targeted.

Policy Template: Block Legacy Authentication

Legacy authentication bypasses modern MFA and should be blocked after impact review.

Connect-MgGraph -Scopes "AuditLog.Read.All","Policy.Read.All"
Get-MgAuditLogSignIn -Top 100 | Where-Object { $_.ClientAppUsed -match 'Other|IMAP|POP|SMTP' }
Get-MgIdentityConditionalAccessPolicy -All | Where-Object { $_.DisplayName -match 'legacy|basic' }

Rollout notes

  • Identify old mail clients and scanners before enforcement.
  • Exclude only approved transition accounts temporarily.
  • Prefer app modernization over permanent exceptions.

Policy Template: Require MFA for All Users

Broad MFA should be staged by group, department, or risk profile. Do not enable for everyone without help desk readiness.

Connect-MgGraph -Scopes "User.Read.All","AuditLog.Read.All","Policy.Read.All"
Get-MgUser -Filter "accountEnabled eq true" -Property Id,DisplayName,UserPrincipalName
Get-MgAuditLogSignIn -Top 100 | Select-Object UserPrincipalName,ConditionalAccessStatus,Status

Rollout pattern

  • Pilot users.
  • IT department.
  • High-risk departments.
  • All remaining staff.
  • Guests and external users after business-owner review.

Monitoring and Evidence

Operational monitoring should focus on blocked users, unexpected app impact, risky sign-ins, and emergency account activity.

Connect-MgGraph -Scopes "AuditLog.Read.All","Policy.Read.All"
Get-MgAuditLogSignIn -Top 100 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus,Status
Get-MgIdentityConditionalAccessPolicy -All | Select-Object DisplayName,State,ModifiedDateTime

Evidence pack

  • Policy export before and after enforcement.
  • Sign-in failures after enforcement.
  • Help desk ticket trend.
  • Break-glass sign-in alert status.
  • Exception list with owner and expiration date.

Rollback Playbook

Rollback must be written before enforcement. The safest rollback disables only the newest or changed policy first.

Connect-MgGraph -Scopes "Policy.Read.All","AuditLog.Read.All"
Get-MgIdentityConditionalAccessPolicy -All | Select-Object Id,DisplayName,State,ModifiedDateTime
Get-MgAuditLogSignIn -Top 50 | Select-Object CreatedDateTime,UserPrincipalName,ConditionalAccessStatus,Status

Rollback order

  1. Confirm the affected users and application.
  2. Identify the newest changed policy.
  3. Disable or revert that policy.
  4. Confirm sign-in recovery.
  5. Preserve logs and incident notes.
  6. Re-stage in report-only before retrying.

Change Checklist

  • Baseline policies exported.
  • Break-glass accounts verified.
  • Scope reviewed by business owner.
  • Report-only results reviewed.
  • Help desk briefed.
  • Rollback owner assigned.
  • Enforcement window approved.
  • Post-change monitoring completed.