Microsoft 365 Conditional Access

Conditional Access in Microsoft 365 is a critical security feature that enables organisations to control access to resources based on specific conditions. It evaluates various factors such as user identity, location, device compliance, application being accessed, and risk level before granting access.

Need help?

Contact Us
Conditional Access
Conditional Access
Microsoft 365 Conditional Access

What is Conditional Access?

Conditional Access in Microsoft 365 is a critical security feature that enables organisations to control access to resources based on specific conditions. It evaluates various factors such as user identity, location, device compliance, application being accessed, and risk level before granting access.

By applying Conditional Access policies, organisations can enforce multi-factor authentication (MFA), block access from untrusted locations, restrict access to compliant devices, and tailor access requirements to different user roles. This helps protect against unauthorised access, reduces the risk of data breaches, and ensures that only the right users have the right level of access to corporate resources.

Conditional Access is part of Microsoft Entra ID (formerly Azure AD) and requires an Azure AD Premium license, which is also bundled in the Enterprise Mobility and Security Suite.

Key Features

Key Features of Conditional Access

Control who can access what, from where, and under what conditions

Identity-Based Controls

Control access based on user identity, group membership, and role. Include or exclude specific users from policies as needed.

Location-Based Restrictions

Block or allow access based on IP addresses and geographic locations — restrict Office 365 to your company offices.

Device Compliance

Require devices to be Intune-compliant or Hybrid Azure AD joined before granting access to corporate resources.

Application-Level Control

Apply policies to specific cloud apps — control access to Exchange Online, SharePoint, Teams, or all Microsoft 365 apps.

Client App Restrictions

Control which applications users can connect from — allow browsers but disable mobile and desktop Outlook apps.

Sign-In Risk Detection

Block sign-ins if Azure detects unusual behaviour — such as simultaneous logins from different countries within minutes.

Multi-Factor Authentication

Enforce MFA via phone call, text message, or mobile app — adding an extra layer of security to the login process.

Device Filtering

Filter devices by ownership (personal vs company) and compliance status to apply granular access controls.

Session Management

Control persistent browser sessions and sign-in frequency — ensure sessions are logged out on non-managed PCs.

Why is Conditional Access Needed?

Microsoft 365 offers fantastic benefits over traditional on-premise infrastructure — no costly infrastructure required, 100 GB mailbox, online meetings, document collaboration, 99.9% uptime, flexibility, and anytime/anywhere access to emails, documents, contacts, and calendars on any device.

Security Concerns with Out-of-the-Box Settings:

  • Office 365 can be accessed from anywhere — not just in the office, anywhere there is internet access.
  • Office 365 can be accessed from any device — not just corporate owned devices, any device (Personal Windows/Mac laptop, tablet, phone, any device with a browser or Outlook client installed).
  • Office 365 can be accessed by just a username and password.

Data Loss Prevention Issues:

  • Emails can be cached offline and copied elsewhere on a home PC with Outlook.
  • Mail can be downloaded to mobile devices and copied to other locations.
  • OneDrive for Business can be synced offline to a home PC and all data copied elsewhere/shared.
  • SharePoint Online can be synced offline to a home PC and all data copied elsewhere/shared.
  • Multi-factor is not turned on by default for Office 365 — To login only a username and password is required.

The Solution

Microsoft introduced Conditional Access to resolve this problem. Conditional Access allows administrators to control what Office 365 apps users can gain access to based on if they pass/fail certain conditions.

Learn More from Microsoft →

Policy Conditions

The following conditions can be controlled by Conditional Access policies

Users/Groups

What users do you want to control — Users can be included/excluded from the policy if required. You will always get the person who is too important for this policy and wants to access everything from their personal iPad. It also allows you to test policies before rolling out to the wider business avoiding locking everyone out!

Cloud Apps

What apps do you want to control? Conditional Access does not need to apply to all of Office 365, you can be more granular and just control access to specific apps — E.g. Exchange Online.

Client App

Control what app/software the user is connecting from to the data — E.g. allow browsers but disable mobile and desktop Outlook apps.

Device Platform

Control what devices users can connect from — E.g. allow Windows and iOS but block Android phones.

Location

Control what IPs can connect to Office 365 — E.g. could limit this to the office external IP.

Sign-In Risk

Control sign-ins if Office 365/Azure thinks the sign-in is not coming from the genuine user — E.g. if someone signs in from London then New York 30 mins later.

Access Grant Controls

Based on the conditions above, access can be allowed with the following controls

Require Multi-Factor Authentication

User is allowed in but will need to complete additional security to log in, e.g. phone call, text message, or mobile app.

Require Device to be Marked as Compliant

Device must be Intune compliant — the device must match the Intune compliance policies to be able to connect.

Require Domain Joined (Hybrid Azure AD)

Devices must be Hybrid Azure AD joined — Mobile Devices Azure AD registered and domain joined machines are set to automatically register in their Azure AD.

Require Approved App

Access is only granted if a connection attempt was made by an approved client app. These apps support Mobile Application Management (MAM) policies, so administrators can wrap security around these apps.

Recommended Conditional Access Policies

Step-by-step deployment guides for the most common Conditional Access policies

Gotchas

As with most Microsoft solutions, Conditional Access is not without its flaws.

Client App Compatibility

Not all client apps support Conditional Access — the Client App needs to support Modern Authentication. e.g. Outlook 2016 or Outlook 2013 (with a reg key change). Outlook 2010 will not work with Conditional Access and the user will be allowed to connect in.

Legacy App Pressure

Upgrade to Outlook 2016 if your business is still using this. Any 3rd party apps (e.g. Outlook Plugins) that don't support above Outlook 2010, put pressure on the vendor to fix this. Don't let your Office 365 migration be hindered by a non-future-proof app.

Benefits of Conditional Access

Why organisations implement Conditional Access for Microsoft 365

Protect Against Unauthorised Access

Conditional Access ensures that only verified users and compliant devices can access corporate resources, significantly reducing the risk of data breaches.

Enforce Multi-Factor Authentication

Require additional verification beyond just a username and password, adding a critical layer of security to the login process.

Control Access by Location

Restrict Office 365 access to specific geographic locations or corporate IP ranges, preventing access from untrusted networks.

Device-Level Security

Ensure only Intune-compliant and company-owned devices can access corporate data, blocking personal and unmanaged devices.

Granular Application Control

Apply security policies to specific apps rather than all of Office 365, allowing tailored access controls for different business needs.

Zero Trust Security Model

Implement a comprehensive Zero Trust approach by combining identity, location, device, and risk signals to make access decisions.

Frequently Asked Questions

Common questions about Microsoft 365 Conditional Access

Chat on WhatsApp
Chat on Messenger
Visit our Facebook page
Visit our LinkedIn page