Skip to content
← Back to the guide

Entra ID Conditional Access design

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

Entra ID Conditional Access design

Designing a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

What Conditional Access policies should every tenant have?

A baseline usually has: require MFA for all users, require phishing-resistant MFA for admins, block legacy authentication, require compliant or hybrid-joined devices for corporate access, block or restrict high-risk sig…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

How many Conditional Access policies is too many?

There is no hard limit that matters (the cap is 195 per tenant), but more than about 20–30 becomes hard to reason about because every sign-in evaluates all of them. Prefer fewer, broader policies scoped with exclusions…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

What does report-only mode do in Conditional Access?

Report-only evaluates the policy on every sign-in and records what it would have done — grant, block, require MFA — in the sign-in log's Report-only tab, without enforcing anything. It is the safe way to see the impact…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

Legacy protocols

Reach for: Block legacy authentication CA policy

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Weak MFA methods

Reach for: Authentication strengths (phishing-resistant)

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

Untrusted device

Reach for: Require compliant device or hybrid-joined

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

Untrusted network

Reach for: Named location + Trusted Locations or Global Secure Access

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-conditional-access-design

Slide 8Download PNG

Auto-generated from Entra ID Conditional Access design. This page is not indexed and isn't part of the guide itself.