The 12 Conditional Access Policies Every Microsoft 365 Tenant Needs in 2026
houssem Makhlouf
0:00 / 0:00
The 12 Conditional Access Policies Every Microsoft 365 Tenant Needs in 2026
7 просмотров · 4 дня назад
houssem Makhlouf
1 подписчик
7 просмотров · 4 дня назад
Twelve Conditional Access policies, built from scratch in a real Microsoft Entra
ID tenant — and every one of them left in Report-only, because that is the only
order that locks nobody out.
No slides of theory. The portal, the real forms, the real traps: the panel that
stays greyed out until you click Yes, the checkbox that carries the country name
on the row and not on the box, the "All resources" that quietly includes the
admin portal you are standing in.
▬▬ What gets built ▬▬
01 Block legacy authentication
02 Require MFA for everyone
03 Phishing-resistant MFA for privileged directory roles
04 Protect the Microsoft admin portals
05 Require a compliant device
06 Sign-in risk (Entra ID P2)
07 User risk (Entra ID P2)
08 Protect security information registration
09 Block sign-in outside permitted countries
10 Require MFA to register or join a device
11 Block unmanaged device platforms
12 Require app protection on mobile
Plus the object that matters more than any of them: a break-glass exclusion
group, created BEFORE the first policy and excluded from all twelve.
▬▬ The part most walkthroughs skip ▬▬
Creating the policies is the easy half. Nothing here is enforced:
1. Leave every policy in Report-only for 7 to 14 days — long enough to cover a
full working cycle, holidays and month-end included.
2. Read what they WOULD have done: Conditional Access → Insights and reporting,
and the sign-in logs. This is where you find the rule you scoped wider than
you meant to.
3. Enable in waves. One policy at a time, watching between each. Legacy
authentication first because nothing legitimate should be using it. The
compliant-device rule last, because it is the one most likely to surprise you.
4. Only then decide, policy by policy: keep, tune, or drop — on what the logs
show you, not on what you intended when you wrote it.
Report-only is not a draft stage you may skip. It is the only mechanism that
lets you be wrong without locking yourself out of your own tenant.
▬▬ Prerequisites ▬▬
• Entra ID P1 for the baseline
• Entra ID P2 for the two risk policies (06, 07)
• Intune for the compliant-device signal (05)
• Conditional Access Administrator or Security Administrator
• Two break-glass accounts — created off camera, and that is deliberate: an
emergency account demonstrated on video is no longer an emergency account.
▬▬ Chapters ▬▬
0:00 Intro — what this is
0:26 What we will build (agenda)
1:16 Where it happens
1:36 How the twelve policies are built
2:00 1 · What this tenant already has
2:38 2 · Create the exclusion group FIRST
3:14 3 · Block legacy authentication
4:05 4 · Require MFA for everyone
4:42 5 · Phishing-resistant MFA for admins
5:38 6 · Protect the admin portals
6:23 7 · Require a compliant device
6:59 8 · Sign-in risk
7:46 9 · User risk
8:31 10 · Protect security info registration
9:14 11 · Geo-blocking with a named location
10:16 12 · Require MFA to join a device
10:57 13 · Block unmanaged device platforms
11:44 14 · App protection on mobile
12:32 15 · What If, then enable in waves
13:42 What happens next — measure, enable, decide
▬▬ Notes ▬▬
Tenant identifiers are blurred throughout. The narration is read by a synthetic
voice; the screen recording is unedited and unaccelerated.
Microsoft Learn — Common Conditional Access policies:
https://learn.microsoft.com/entra/identity...
Microsoft Learn — Insights and reporting:
https://learn.microsoft.com/entra/identity...