Learning state
Track this guide
Saved in this browser only. No account required.
Conditional Access Master Class
Production-ready Microsoft Entra Conditional Access guide for safe report-only validation, break-glass protection, staged enforcement, policy templates, monitoring, and rollback.
Table of Contents
- Operating Model
- Baseline Inventory
- Break-Glass Protection
- Report-Only Rollout
- Policy Template: Require MFA for Administrators
- Policy Template: Block Legacy Authentication
- Policy Template: Require MFA for All Users
- Monitoring and Evidence
- Rollback Playbook
- Change Checklist
Operating Model
Conditional Access is a production access-control system. A bad policy can block administrators, service accounts, automations, mobile users, or entire departments. The safe operating model is to inventory first, stage in report-only mode, pilot with a known group, and enforce only after sign-in evidence has been reviewed.
Golden rules
- Maintain at least two cloud-only break-glass accounts.
- Exclude break-glass accounts intentionally and document the exclusion.
- Start every new policy in report-only mode.
- Never target all users and all cloud apps without a pilot window.
- Record rollback steps before enabling enforcement.
Connect-MgGraph -Scopes "Policy.Read.All","AuditLog.Read.All","Directory.Read.All"
Get-MgIdentityConditionalAccessPolicy -All | Select-Object Id,DisplayName,State,CreatedDateTime,ModifiedDateTime
Get-MgAuditLogSignIn -Top 20 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus
Baseline Inventory
Inventory tells you what exists before you propose a new control. Capture policies, named locations, users, groups, role assignments, and recent sign-in failures.
Connect-MgGraph -Scopes "Policy.Read.All","Directory.Read.All","AuditLog.Read.All","RoleManagement.Read.Directory"
Get-MgIdentityConditionalAccessPolicy -All
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabled,UserType
Get-MgDirectoryRole -All | Select-Object Id,DisplayName
Get-MgAuditLogSignIn -Top 50
Evidence to save
- Policy name, state, assignments, controls, and session settings.
- Groups targeted or excluded by each policy.
- Recent sign-ins where
ConditionalAccessStatusis failure or notApplied. - Guest and service-account patterns.
- Administrator role membership.
Break-Glass Protection
Break-glass accounts keep the tenant recoverable when Conditional Access, MFA, federation, device compliance, or network controls fail.
Connect-MgGraph -Scopes "User.Read.All","Policy.Read.All","AuditLog.Read.All"
Get-MgUser -Filter "startsWith(displayName,'Break Glass')" -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Get-MgIdentityConditionalAccessPolicy -All | Select-Object DisplayName,State
Get-MgAuditLogSignIn -Top 50 | Where-Object { $_.UserPrincipalName -like '*break*' }
Requirements
- Two cloud-only accounts.
- Long vaulted passwords.
- No routine use.
- Excluded from policies that can block recovery.
- Alert on every sign-in attempt.
- Tested recovery procedure.
Report-Only Rollout
Report-only mode is the safest way to test policy effect. Operators should review impact before enforcement.
Rollout sequence
- Draft policy with narrow scope.
- Set state to report-only.
- Wait through a normal business cycle.
- Review sign-in log impact.
- Pilot with a small group.
- Expand target group.
- Enable enforcement.
- Watch sign-in logs for failures.
Connect-MgGraph -Scopes "Policy.Read.All","AuditLog.Read.All"
Get-MgIdentityConditionalAccessPolicy -All | Where-Object { $_.State -eq 'enabledForReportingButNotEnforced' }
Get-MgAuditLogSignIn -Top 100 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus
Policy Template: Require MFA for Administrators
This should usually be the first enforced policy because privileged accounts carry the highest blast radius.
Target
- Include directory roles for administrators.
- Exclude break-glass accounts.
- Require multifactor authentication.
- Start as report-only.
Connect-MgGraph -Scopes "Policy.Read.All","RoleManagement.Read.Directory"
Get-MgDirectoryRole -All | Sort-Object DisplayName
Get-MgIdentityConditionalAccessPolicy -All | Select-Object DisplayName,State
Validation
- Admin sign-ins show MFA required in report-only impact.
- Break-glass accounts remain reachable.
- Service accounts are not accidentally targeted.
Policy Template: Block Legacy Authentication
Legacy authentication bypasses modern MFA and should be blocked after impact review.
Connect-MgGraph -Scopes "AuditLog.Read.All","Policy.Read.All"
Get-MgAuditLogSignIn -Top 100 | Where-Object { $_.ClientAppUsed -match 'Other|IMAP|POP|SMTP' }
Get-MgIdentityConditionalAccessPolicy -All | Where-Object { $_.DisplayName -match 'legacy|basic' }
Rollout notes
- Identify old mail clients and scanners before enforcement.
- Exclude only approved transition accounts temporarily.
- Prefer app modernization over permanent exceptions.
Policy Template: Require MFA for All Users
Broad MFA should be staged by group, department, or risk profile. Do not enable for everyone without help desk readiness.
Connect-MgGraph -Scopes "User.Read.All","AuditLog.Read.All","Policy.Read.All"
Get-MgUser -Filter "accountEnabled eq true" -Property Id,DisplayName,UserPrincipalName
Get-MgAuditLogSignIn -Top 100 | Select-Object UserPrincipalName,ConditionalAccessStatus,Status
Rollout pattern
- Pilot users.
- IT department.
- High-risk departments.
- All remaining staff.
- Guests and external users after business-owner review.
Monitoring and Evidence
Operational monitoring should focus on blocked users, unexpected app impact, risky sign-ins, and emergency account activity.
Connect-MgGraph -Scopes "AuditLog.Read.All","Policy.Read.All"
Get-MgAuditLogSignIn -Top 100 | Select-Object CreatedDateTime,UserPrincipalName,AppDisplayName,ConditionalAccessStatus,Status
Get-MgIdentityConditionalAccessPolicy -All | Select-Object DisplayName,State,ModifiedDateTime
Evidence pack
- Policy export before and after enforcement.
- Sign-in failures after enforcement.
- Help desk ticket trend.
- Break-glass sign-in alert status.
- Exception list with owner and expiration date.
Rollback Playbook
Rollback must be written before enforcement. The safest rollback disables only the newest or changed policy first.
Connect-MgGraph -Scopes "Policy.Read.All","AuditLog.Read.All"
Get-MgIdentityConditionalAccessPolicy -All | Select-Object Id,DisplayName,State,ModifiedDateTime
Get-MgAuditLogSignIn -Top 50 | Select-Object CreatedDateTime,UserPrincipalName,ConditionalAccessStatus,Status
Rollback order
- Confirm the affected users and application.
- Identify the newest changed policy.
- Disable or revert that policy.
- Confirm sign-in recovery.
- Preserve logs and incident notes.
- Re-stage in report-only before retrying.
Change Checklist
- Baseline policies exported.
- Break-glass accounts verified.
- Scope reviewed by business owner.
- Report-only results reviewed.
- Help desk briefed.
- Rollback owner assigned.
- Enforcement window approved.
- Post-change monitoring completed.