Microsoft 365 Conditional Access
Conditional Access in Microsoft 365 is a critical security feature that enables organisations to control access to resources based on specific conditions. It evaluates various factors such as user identity, location, device compliance, application being accessed, and risk level before granting access.
Need help?
Contact Us
What is Conditional Access?
Conditional Access in Microsoft 365 is a critical security feature that enables organisations to control access to resources based on specific conditions. It evaluates various factors such as user identity, location, device compliance, application being accessed, and risk level before granting access.
By applying Conditional Access policies, organisations can enforce multi-factor authentication (MFA), block access from untrusted locations, restrict access to compliant devices, and tailor access requirements to different user roles. This helps protect against unauthorised access, reduces the risk of data breaches, and ensures that only the right users have the right level of access to corporate resources.
Conditional Access is part of Microsoft Entra ID (formerly Azure AD) and requires an Azure AD Premium license, which is also bundled in the Enterprise Mobility and Security Suite.
Key FeaturesKey Features of Conditional Access
Control who can access what, from where, and under what conditions
Identity-Based Controls
Control access based on user identity, group membership, and role. Include or exclude specific users from policies as needed.
Location-Based Restrictions
Block or allow access based on IP addresses and geographic locations — restrict Office 365 to your company offices.
Device Compliance
Require devices to be Intune-compliant or Hybrid Azure AD joined before granting access to corporate resources.
Application-Level Control
Apply policies to specific cloud apps — control access to Exchange Online, SharePoint, Teams, or all Microsoft 365 apps.
Client App Restrictions
Control which applications users can connect from — allow browsers but disable mobile and desktop Outlook apps.
Sign-In Risk Detection
Block sign-ins if Azure detects unusual behaviour — such as simultaneous logins from different countries within minutes.
Multi-Factor Authentication
Enforce MFA via phone call, text message, or mobile app — adding an extra layer of security to the login process.
Device Filtering
Filter devices by ownership (personal vs company) and compliance status to apply granular access controls.
Session Management
Control persistent browser sessions and sign-in frequency — ensure sessions are logged out on non-managed PCs.
Why is Conditional Access Needed?
Microsoft 365 offers fantastic benefits over traditional on-premise infrastructure — no costly infrastructure required, 100 GB mailbox, online meetings, document collaboration, 99.9% uptime, flexibility, and anytime/anywhere access to emails, documents, contacts, and calendars on any device.
Security Concerns with Out-of-the-Box Settings:
- Office 365 can be accessed from anywhere — not just in the office, anywhere there is internet access.
- Office 365 can be accessed from any device — not just corporate owned devices, any device (Personal Windows/Mac laptop, tablet, phone, any device with a browser or Outlook client installed).
- Office 365 can be accessed by just a username and password.
Data Loss Prevention Issues:
- Emails can be cached offline and copied elsewhere on a home PC with Outlook.
- Mail can be downloaded to mobile devices and copied to other locations.
- OneDrive for Business can be synced offline to a home PC and all data copied elsewhere/shared.
- SharePoint Online can be synced offline to a home PC and all data copied elsewhere/shared.
- Multi-factor is not turned on by default for Office 365 — To login only a username and password is required.
The Solution
Microsoft introduced Conditional Access to resolve this problem. Conditional Access allows administrators to control what Office 365 apps users can gain access to based on if they pass/fail certain conditions.
Learn More from Microsoft →Policy Conditions
The following conditions can be controlled by Conditional Access policies
Users/Groups
What users do you want to control — Users can be included/excluded from the policy if required. You will always get the person who is too important for this policy and wants to access everything from their personal iPad. It also allows you to test policies before rolling out to the wider business avoiding locking everyone out!
Cloud Apps
What apps do you want to control? Conditional Access does not need to apply to all of Office 365, you can be more granular and just control access to specific apps — E.g. Exchange Online.
Client App
Control what app/software the user is connecting from to the data — E.g. allow browsers but disable mobile and desktop Outlook apps.
Device Platform
Control what devices users can connect from — E.g. allow Windows and iOS but block Android phones.
Location
Control what IPs can connect to Office 365 — E.g. could limit this to the office external IP.
Sign-In Risk
Control sign-ins if Office 365/Azure thinks the sign-in is not coming from the genuine user — E.g. if someone signs in from London then New York 30 mins later.
Access Grant Controls
Based on the conditions above, access can be allowed with the following controls
Require Multi-Factor Authentication
User is allowed in but will need to complete additional security to log in, e.g. phone call, text message, or mobile app.
Require Device to be Marked as Compliant
Device must be Intune compliant — the device must match the Intune compliance policies to be able to connect.
Require Domain Joined (Hybrid Azure AD)
Devices must be Hybrid Azure AD joined — Mobile Devices Azure AD registered and domain joined machines are set to automatically register in their Azure AD.
Require Approved App
Access is only granted if a connection attempt was made by an approved client app. These apps support Mobile Application Management (MAM) policies, so administrators can wrap security around these apps.
Recommended Conditional Access Policies
Step-by-step deployment guides for the most common Conditional Access policies
Ensure users are only able to access the Microsoft 365 system if they have multi-factor authentication setup for their account.
Steps:
- 1.Sign in to the Entra ID Portal: Go to https://entra.microsoft.com/ and sign in with an account that has administrative privileges.
- 2.Navigate to Protection: In the left-hand menu, click on "Protection".
- 3.Conditional Access: Under the protection menu, select "Conditional Access".
- 4.New Policy: Select "New Policy from Template".
- 5.Secure Foundation: Select "Secure Foundation" from the top menu.
- 6.Require multifactor authentication for all users: Select "Require multifactor authentication for all users" from the items below.
- 7.Adjust Policy state and save: Set policy name as per your requirements (e.g. "CA01 – Require multifactor Authentication for all users"). Set policy state to off, on, or report only. Save the policy once you are happy with the settings.
Ensure users are only able to access the Microsoft 365 system from their country, and block access to all other countries.
Steps:
- 1.Sign in to the Entra ID Portal: Go to https://entra.microsoft.com/ and sign in with an account that has administrative privileges.
- 2.Navigate to Protection: In the left-hand menu, click on "Protection".
- 3.Conditional Access: Under the protection menu, select "Conditional Access".
- 4.Named Locations: Once in the conditional access main menu, select "Named Locations".
- 5.Navigate to Countries location: In the top menu, click on "Countries location".
- 6.Country Selection: Enter the name "Approved Countries". In the right hand menu, select the countries where your offices are located.
- 7.Save Selection: Save your selection by selecting "create".
- 8.Create policy: Select "New Policy" from the top menu.
- 9.Name Policy: Set name of policy (e.g. "CA02 – Block Access from Other Countries").
- 10.Users to affect: In the "Users" menu, set the include sub menu to "all users".
- 11.Exclude admin account: To ensure you are never locked out of your Microsoft 365 tenant, select the sub menu "exclude" then select your administrator account.
- 12.Client Apps: Select Client apps. Set configure to yes. De-select "Exchange ActiveSync Clients" & "Other Clients".
- 13.Set Filter for devices: Select the "Filter for devices" menu. Select yes on the "Configure" menu. Select "exclude filtered devices from policy". Set property to "IsCompliant", Operator to "equals", Value to "True". Then select Done.
- 14.Block Access: Select "Grant" menu item. Select "block access". Set "Enable policy" to "on".
Ensure users are only able to access the Microsoft 365 system from specific device types, and block access from un-approved device types.
Steps:
- 1.Select "Policies" from the Conditional Access Control Panel.
- 2.Select "New Policy" from top menu.
- 3.Name policy "CA03 – Block un-approved Device types".
- 4.Select "Users" Menu and then select "All users".
- 5.Select "Target Resources" then select "All Cloud Apps".
- 6.Select "Conditions" and then "Device Platforms".
- 7.Set Configure to "yes" and then tick "Windows Phone" & "Linux".
- 8.Select "done".
- 9.Select "Grant" from left hand menu and then set to "Block Access", click "select" from the bottom.
- 10.Set policy to "on".
- 11.Select "Create".
Ensure when users close a browser on a non-managed PC, the session will be logged out from Microsoft 365.
Steps:
- 1.Select "New Policy".
- 2.Name the policy "CA04 – Disable Persistent Browser sessions".
- 3.Select "users" from right hand menu and then select "all users".
- 4.Select "Target Resources" then select "All Cloud Apps".
- 5.Select "Conditions" from left hand menu.
- 6.Select "Client Apps" from middle menu.
- 7.Set configure to "yes" and then tick "Browser", then select "done".
- 8.Select "Session" from right hand side menu, then tick "Persistent Browser Session". Then set the drop down menu to "Never Persistent".
- 9.Click "Select".
- 10.Set Policy to "On" and then click "Create".
Ensure that client devices are using an App Protection Policy when accessing your corporate data.
Steps:
- 1.Select "New Policy".
- 2.Name the policy "CA05 – Require App Protection Policy".
- 3.Select "users" from right hand menu and then select "all users".
- 4.Select "Target Resources" then click "Select Apps".
- 5.Click "Select" from the menu items.
- 6.On the right hand menu tick "Office 365" then "select".
- 7.Select "Conditions" from right hand side menu, then select "Device Platform". Then set the right hand side menu configure option to "yes".
- 8.Tick "Android" and "IOS" from the options. Then click "Done".
- 9.Select "Client Apps" from the middle menu.
- 10.Set Configure on right hand side menu to "yes", then click "browser" and "Mobile Apps and Desktop Clients". Select "done".
- 11.Select "Grant Access" from left hand menu, then select "Require App protection Policy" from right hand side. Then click "Select".
- 12.Set policy to "on" and then click "Create".
Block older protocols from being able to access your Microsoft 365 tenant.
Steps:
- 1.Select "New Policy from Template".
- 2.Select "Block Legacy Authentication".
- 3.Name the policy "CA06 – Block Legacy Authentication".
- 4.Set Policy state to "on".
- 5.Click on Create.
Enforce multi-factor authentication when users are joining a device to Entra ID.
Steps:
- 1.Select "New Policy".
- 2.Name the policy "CA07 – Require MFA to Join to Entra".
- 3.Select "users" from right hand menu and then select "all users".
- 4.Select "Target Resources" then click the drop down menu. Select the "user actions" option, then tick "register or join devices".
- 5.Select "Grant" from the left hand menu, then select "grant access" from right hand menu.
- 6.Tick "require multifactor authentication" then "select".
- 7.Set policy to "on" and then click "create".
Block access to the Microsoft 365 system from personal computers.
Steps:
- 1.Select "New Policy".
- 2.Name the policy "CA08 – Block Personal Devices".
- 3.Select "users" from right hand menu and then select "all users".
- 4.Select the "Exclude" menu, select "users and groups", enter your admin account.
- 5.Select "Target Resources" and select "all cloud apps".
- 6.Select "Conditions" menu, then select "device platforms". Select "Yes" under the configure option on the right hand side. Then tick "Windows" and "macOS". Select "done".
- 7.Select "Client apps", set configure to "yes", tick "browser", "mobile apps and desktop clients", "exchange Active Sync clients" and "other clients".
- 8.Select "Filter for devices". Set to "yes" under configure. Set the expressions to: device ownership – equals – personal OR deviceownership – not equals – company. Select "done".
- 9.Select "Grant", select "Block Access" on right hand side. Click "select".
- 10.Set Enable policy to "report only".
- 11.Review and enable once settings are confirmed.
Restrict access so that users can only connect to Office 365 if they are coming from the corporate IP range (external).
Steps:
- 1.Navigate to Azure Active Directory in the Azure Portal.
- 2.Under the Manage section, click on Security, then select Conditional Access.
- 3.Click the + New Policy button at the top of the page.
- 4.Give the policy a meaningful name, such as "Restrict Access to Company Offices".
- 5.Under Assignments, click on Users and groups. Choose all users or specific security groups.
- 6.Under Assignments, select Cloud apps or actions. Choose all Microsoft 365 apps or All cloud apps.
- 7.Under Assignments, click on Conditions, then select Locations.
- 8.Set Configure to Yes. Click on Include, then choose Any location. Click on Exclude, then select your corporate IP range.
- 9.Under Access controls, click Grant. Select Grant access, and enable Require multi-factor authentication if necessary.
- 10.Set the Enable policy switch to On.
- 11.Review your settings, then click Create to apply the policy.
Gotchas
As with most Microsoft solutions, Conditional Access is not without its flaws.
Client App Compatibility
Not all client apps support Conditional Access — the Client App needs to support Modern Authentication. e.g. Outlook 2016 or Outlook 2013 (with a reg key change). Outlook 2010 will not work with Conditional Access and the user will be allowed to connect in.
Legacy App Pressure
Upgrade to Outlook 2016 if your business is still using this. Any 3rd party apps (e.g. Outlook Plugins) that don't support above Outlook 2010, put pressure on the vendor to fix this. Don't let your Office 365 migration be hindered by a non-future-proof app.
Useful Links
• Conditional Access Overview
Learn about Microsoft Entra Conditional Access — the if-then statement engine that controls access to resources based on conditions.
Read More →• Plan a Conditional Access Deployment
Microsoft's guide for planning and deploying Conditional Access policies in your organisation effectively.
Read More →• Common Conditional Access Policies
Explore common Conditional Access policy examples including requiring MFA, blocking legacy authentication, and more.
Read More →• Conditional Access Documentation
Full Microsoft documentation for Conditional Access — including how-to guides, troubleshooting, and deployment best practices.
Read More →Benefits of Conditional Access
Why organisations implement Conditional Access for Microsoft 365
Protect Against Unauthorised Access
Conditional Access ensures that only verified users and compliant devices can access corporate resources, significantly reducing the risk of data breaches.
Enforce Multi-Factor Authentication
Require additional verification beyond just a username and password, adding a critical layer of security to the login process.
Control Access by Location
Restrict Office 365 access to specific geographic locations or corporate IP ranges, preventing access from untrusted networks.
Device-Level Security
Ensure only Intune-compliant and company-owned devices can access corporate data, blocking personal and unmanaged devices.
Granular Application Control
Apply security policies to specific apps rather than all of Office 365, allowing tailored access controls for different business needs.
Zero Trust Security Model
Implement a comprehensive Zero Trust approach by combining identity, location, device, and risk signals to make access decisions.
Frequently Asked Questions
Common questions about Microsoft 365 Conditional Access
Conditional Access is a security feature in Microsoft Entra ID that controls access to resources based on specific conditions such as user identity, location, device compliance, and risk level. It allows organisations to enforce policies like MFA, device compliance, and location-based restrictions.
Yes. Conditional Access requires an Azure AD Premium license (P1 or P2), which is also included in the Enterprise Mobility and Security Suite (EMS) or Microsoft 365 E3/E5 licenses.
Yes. Each policy allows you to include or exclude specific users or groups. It's recommended to always exclude your admin account from block policies to avoid being locked out.
If a user doesn't meet the conditions defined in the policy, access will be blocked. The user will see an error message indicating they don't meet the requirements to access the resource.
Yes. You can set a policy to "Report-only" mode, which allows you to see the impact of the policy without actually enforcing it. This helps you test and verify before going live.