Перейти к содержимому

The 12 Conditional Access Policies Every Microsoft 365 Tenant Needs in 2026

houssem Makhlouf

0:00 / 0:00

The 12 Conditional Access Policies Every Microsoft 365 Tenant Needs in 2026

7 просмотров · 4 дня назад
houssem Makhlouf
1 подписчик
7 просмотров · 4 дня назад
Twelve Conditional Access policies, built from scratch in a real Microsoft Entra ID tenant — and every one of them left in Report-only, because that is the only order that locks nobody out. No slides of theory. The portal, the real forms, the real traps: the panel that stays greyed out until you click Yes, the checkbox that carries the country name on the row and not on the box, the "All resources" that quietly includes the admin portal you are standing in. ▬▬ What gets built ▬▬ 01 Block legacy authentication 02 Require MFA for everyone 03 Phishing-resistant MFA for privileged directory roles 04 Protect the Microsoft admin portals 05 Require a compliant device 06 Sign-in risk (Entra ID P2) 07 User risk (Entra ID P2) 08 Protect security information registration 09 Block sign-in outside permitted countries 10 Require MFA to register or join a device 11 Block unmanaged device platforms 12 Require app protection on mobile Plus the object that matters more than any of them: a break-glass exclusion group, created BEFORE the first policy and excluded from all twelve. ▬▬ The part most walkthroughs skip ▬▬ Creating the policies is the easy half. Nothing here is enforced: 1. Leave every policy in Report-only for 7 to 14 days — long enough to cover a full working cycle, holidays and month-end included. 2. Read what they WOULD have done: Conditional Access → Insights and reporting, and the sign-in logs. This is where you find the rule you scoped wider than you meant to. 3. Enable in waves. One policy at a time, watching between each. Legacy authentication first because nothing legitimate should be using it. The compliant-device rule last, because it is the one most likely to surprise you. 4. Only then decide, policy by policy: keep, tune, or drop — on what the logs show you, not on what you intended when you wrote it. Report-only is not a draft stage you may skip. It is the only mechanism that lets you be wrong without locking yourself out of your own tenant. ▬▬ Prerequisites ▬▬ • Entra ID P1 for the baseline • Entra ID P2 for the two risk policies (06, 07) • Intune for the compliant-device signal (05) • Conditional Access Administrator or Security Administrator • Two break-glass accounts — created off camera, and that is deliberate: an emergency account demonstrated on video is no longer an emergency account. ▬▬ Chapters ▬▬ 0:00 Intro — what this is 0:26 What we will build (agenda) 1:16 Where it happens 1:36 How the twelve policies are built 2:00 1 · What this tenant already has 2:38 2 · Create the exclusion group FIRST 3:14 3 · Block legacy authentication 4:05 4 · Require MFA for everyone 4:42 5 · Phishing-resistant MFA for admins 5:38 6 · Protect the admin portals 6:23 7 · Require a compliant device 6:59 8 · Sign-in risk 7:46 9 · User risk 8:31 10 · Protect security info registration 9:14 11 · Geo-blocking with a named location 10:16 12 · Require MFA to join a device 10:57 13 · Block unmanaged device platforms 11:44 14 · App protection on mobile 12:32 15 · What If, then enable in waves 13:42 What happens next — measure, enable, decide ▬▬ Notes ▬▬ Tenant identifiers are blurred throughout. The narration is read by a synthetic voice; the screen recording is unedited and unaccelerated. Microsoft Learn — Common Conditional Access policies: https://learn.microsoft.com/entra/identity... Microsoft Learn — Insights and reporting: https://learn.microsoft.com/entra/identity...