Knowledge Base
Engineer Login
Back to Knowledge Base

Configuring Conditional Access in Azure AD

Microsoft 365 conditional access Azure AD MFA security policy By Cade · Updated 03/05/26 07:51 AM
Conditional Access policies in Azure AD control who can access Microsoft 365 and under what conditions. Common policies: require MFA for all users, require MFA when accessing from outside trusted locations, block access from risky sign-in locations, and require compliant devices. Create policies in Azure AD > Security > Conditional Access > New policy. Policies have Assignments (who and what they apply to) and Access controls (what's required). Use the 'What If' tool to test a policy against a hypothetical sign-in before enabling it. Always test policies in report-only mode first — enabling a misconfigured policy can lock all users out. Exclude your break-glass emergency admin account from all Conditional Access policies (this account exists specifically for emergency access if CA policies cause a lockout). Review Conditional Access sign-in reports weekly to monitor for blocked legitimate access and policy effectiveness.