Configuring Conditional Access in Azure AD
Microsoft 365
conditional access
Azure AD
MFA
security policy
By Cade · Updated 03/05/26 07:51 AM
Conditional Access policies in Azure AD control who can access Microsoft 365 and under what conditions. Common policies: require MFA for all users, require MFA when accessing from outside trusted locations, block access from risky sign-in locations, and require compliant devices.
Create policies in Azure AD > Security > Conditional Access > New policy. Policies have Assignments (who and what they apply to) and Access controls (what's required). Use the 'What If' tool to test a policy against a hypothetical sign-in before enabling it.
Always test policies in report-only mode first — enabling a misconfigured policy can lock all users out. Exclude your break-glass emergency admin account from all Conditional Access policies (this account exists specifically for emergency access if CA policies cause a lockout). Review Conditional Access sign-in reports weekly to monitor for blocked legitimate access and policy effectiveness.