Conditional Access guides
Microsoft Entra's policy engine for allowing, blocking, or stepping up authentication based on signals. See the glossary entry →
51 guides touch on conditional access.
- Adding a named location without breaking Conditional Access
How to add or change a named location in Entra without breaking Conditional Access: MFA and risk side effects, the report-only sequence, the egress-IP trap.
- Azure Virtual Desktop explained
What Azure Virtual Desktop is: host pools, session hosts, multi-session Windows, FSLogix profiles, and when it beats Windows 365 or a physical desktop.
- Business Premium vs Microsoft 365 E3
Business Premium vs Microsoft 365 E3: Premium wins on security for less money, E3 wins on mailboxes, Windows, and scale. How to choose, and how to mix them.
- Compromised Microsoft 365 account response runbook
Compromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
- Conditional Access break-glass account design
How to design break-glass accounts that survive every Conditional Access disaster — credentials, monitoring, and recovery.
- Conditional Access for Microsoft 365 admin accounts
Conditional Access policies for admin accounts: phishing-resistant MFA, managed devices, short sessions, no legacy auth, plus exclusions and rollout order.
- Continuous Access Evaluation explained
How CAE revokes access tokens in near real time when risk signals change — and what to do to make sure it works.
- Cross-tenant synchronization in Entra ID
Cross-tenant synchronization auto-provisions B2B guests between Microsoft Entra ID tenants in a multi-tenant organisation.
- Distribution lists vs Microsoft 365 Groups
How DLs, mail-enabled security groups, and Microsoft 365 Groups differ — and when to use each.
- Entra External ID vs Azure AD B2C
Microsoft has two products for customer identity. Here's the difference and which to pick today.
- Entra ID app registrations and enterprise apps
Two sides of the same coin — app registrations define an app, enterprise apps grant it to your tenant. Here's how they relate.
- Entra ID authentication contexts
Authentication contexts let Conditional Access trigger step-up authentication for specific actions, not just specific apps.
- Entra ID B2B guest access
How Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.
- Entra ID groups and group-based licensing
Group types in Entra ID, dynamic groups, and using groups to assign licences automatically.
- Entra ID Privileged Identity Management
PIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- Entra ID Workload Identities
Workload Identities is Entra ID's product for managing non-human identities — apps, services, scripts — and the risks they create.
- How to block legacy authentication with Conditional Access
How to block legacy authentication in Entra ID with Conditional Access: find who still uses it, build the block policy, run report-only, then enforce.
- How to create a break-glass account in Entra ID
How to create an emergency access (break-glass) account in Entra ID: cloud-only, permanent Global Admin, excluded from Conditional Access, FIDO2 keys, alerting.
- How to require compliant devices with Conditional Access
How to require a compliant or hybrid-joined device with Conditional Access: the Intune compliance policy first, the grant control, exclusions, report-only.
- How to require MFA for all users with Conditional Access
How to require MFA for all users in Entra ID with Conditional Access: the exclusions that matter, report-only rollout, registration campaign, enforcement.
- Hybrid identity strategy for Microsoft 365
How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
- Intune app protection policies
How MAM-WE protects corporate data inside specific apps on personal devices — without managing the device itself.
- Intune baseline for Cloud PCs
A minimum viable Intune configuration for Windows 365 Cloud PCs: enrolment, compliance, configuration profiles, Autopatch, and the differences from laptops.
- Intune compliance policies and Conditional Access
Combining Intune compliance with Conditional Access gives you device-aware access control — the heart of zero trust.
- Investigating a suspicious sign-in with Entra sign-in logs
How to work a suspicious sign-in in the Entra sign-in logs: which log, which columns matter, traveller vs attacker, and when to escalate to compromise.
- Microsoft 365 admin center
The Microsoft 365 admin center: what actually lives there, the specialist portals it hands off to, and the role design that should gate all of it.
- Microsoft 365 dev/test tenant strategy
Why and how to maintain a separate dev/test Microsoft 365 tenant for safe testing of changes.
- Microsoft 365 documentation patterns
What to document for a Microsoft 365 tenant, how to structure it, and how to keep it from rotting.
- Microsoft 365 for enterprise
What changes when Microsoft 365 is deployed at enterprise scale — plans, identity, governance, and lifecycle.
- Microsoft 365 for small business
How to choose, set up, and run Microsoft 365 in a small business — the plan, the basics, and the security baseline.
- Microsoft 365 Lighthouse for MSPs
Microsoft 365 Lighthouse is the multi-tenant management portal for managed service providers running many SMB tenants.
- Microsoft 365 mobile device security
Securing mobile access to Microsoft 365 — MAM, MDM, Conditional Access, and the BYOD vs corporate distinction.
- Microsoft 365 security and compliance
A practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
- Microsoft 365 security baselines
The minimum security configuration every Microsoft 365 tenant should have — and how to get there.
- Microsoft Defender for Cloud Apps explained
Defender for Cloud Apps is Microsoft's CASB — discovering, monitoring, and controlling SaaS app usage.
- Microsoft Entra Global Secure Access
Microsoft's SSE platform — Internet Access and Private Access for zero-trust network access. Here's what it does.
- Microsoft Intune and device management
Microsoft Intune explained: what it manages, how policies work, how enrollment and compliance fit together, and where it sits in Microsoft 365.
- Microsoft Purview Compliance Manager
Compliance Manager scores your tenant against compliance frameworks and tracks improvements over time.
- Microsoft Tunnel for Intune
Microsoft Tunnel provides per-app VPN for managed mobile devices — the Intune-integrated way to access on-prem resources.
- OneDrive for Business vs OneDrive (personal)
Two products, one name — the differences between work and consumer OneDrive, and why mixing them is a bad idea.
- OneDrive Personal Vault
What OneDrive Personal Vault is, why it exists only in consumer OneDrive, and the equivalent protections for sensitive files in a work or school tenant.
- OneDrive sync troubleshooting
A diagnostic ladder for OneDrive sync issues on Windows and macOS — common causes and how to fix them.
- Outlook mobile policies and app protection
How to govern Outlook mobile on iOS and Android — app protection policies, security settings, and feature controls.
- Ransomware preparedness for Microsoft 365
How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.
- SharePoint external sharing
The layered controls that decide who outside your organisation can access SharePoint and OneDrive content — and a sane baseline configuration.
- Testing Conditional Access policies
How to test Conditional Access policies before enforcing them — report-only mode, what-if, and rollout patterns.
- The Entra Suite explained
Entra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays.
- Token protection and token theft in Microsoft 365
Token theft has become a leading attack pattern. Here's how it works and what Microsoft 365 offers to defend against it.
- What is Microsoft Entra ID?
What Microsoft Entra ID is: the identity service behind every Microsoft 365 sign-in, how it relates to Active Directory, and the licensing tiers that matter.
- Windows 365 explained
What Windows 365 is: how Cloud PCs work, the licensing tiers, how it connects to Intune and Entra ID, and when it beats AVD or a physical laptop.
- Zero trust in Microsoft 365
What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.