Most businesses on Microsoft 365 have heard of Conditional Access without fully knowing what it does. It's one of the most useful security controls available in Entra ID (formerly Azure AD) - but it's also commonly misunderstood as a complete security solution on its own, which it isn't.
What Conditional Access Actually Does
Conditional Access lets you set rules that control exactly when, where, and how someone is allowed to sign in to your Microsoft 365 environment. Rather than a single on/off setting, it evaluates conditions at the moment of sign-in - the user, the device, the location, the application being accessed, the detected risk level - and applies a response: allow, block, or require additional verification.
Common Conditional Access Rules Perth Businesses Use
- Require MFA for all sign-ins - the most common baseline rule, enforced consistently rather than left optional.
- Block sign-ins from unexpected countries - if your business has no reason for logins from certain regions, blocking them removes a large chunk of opportunistic attack attempts.
- Require a managed or compliant device - only allowing sign-in from devices enrolled in Intune (or otherwise verified as company-managed), rather than any random device with the right password.
- Require MFA for risky sign-ins specifically - using Microsoft's risk detection to prompt for extra verification only when something looks unusual, rather than every single time.
- Block legacy authentication - older sign-in protocols don't support MFA at all, and disabling them closes a significant, often-overlooked gap.
Why It's "Essential But Not Bulletproof"
Conditional Access controls the front door - but it has real limits worth understanding before relying on it as your only safeguard:
- It can be misconfigured - overly broad exclusions (a common one: exempting a "break glass" admin account and then leaving that exemption in place indefinitely) can quietly undermine the whole policy.
- Session token theft can bypass it - if an attacker steals an active session token through malware or an "adversary in the middle" phishing kit, they can sometimes skirt around the sign-in checks that Conditional Access evaluates.
- It doesn't protect what happens after sign-in - Conditional Access governs access, not behaviour once someone is legitimately logged in.
- Policies need active maintenance - a policy written two years ago for an office-only team may not reflect how the business actually works today.
What Should Sit Alongside It
Conditional Access works best as one layer in a broader approach - paired with phishing-resistant MFA where practical, device management through Intune, and regular review of policy exclusions and exceptions rather than "set and forget."
Where to Start
If your business is on Microsoft 365 Business Premium or above, Conditional Access is already included - the question is usually whether it's actually configured, and configured correctly, rather than left at default settings since the day the tenant was set up.
Frequently Asked Questions
What does Conditional Access actually do?
Conditional Access lets you set rules that control exactly when, where, and how someone is allowed to sign in to your Microsoft 365 environment. It evaluates conditions at the moment of sign-in - the user, device, location, application, and detected risk level - and applies a response: allow, block, or require additional verification.
What are common Conditional Access rules?
Requiring MFA for all sign-ins, blocking sign-ins from unexpected countries, requiring a managed or compliant device, requiring MFA only for risky sign-ins specifically, and blocking legacy authentication protocols that don't support MFA at all.
Is Conditional Access enough on its own?
No. It can be misconfigured through overly broad exclusions, session token theft can sometimes bypass it, it doesn't protect what happens after sign-in, and policies need active maintenance. It works best paired with phishing-resistant MFA, device management, and regular policy review.
Do I already have Conditional Access?
If your business is on Microsoft 365 Business Premium or above, Conditional Access is already included. The real question is usually whether it's actually configured correctly, rather than left at default settings since the tenant was first set up.
We configure and review Conditional Access policies for Perth businesses on Microsoft 365 - not just switched on, but actually fit for how your team works.
Microsoft 365 Services →Not sure if Conditional Access is actually configured for your tenant?
Call 0433 087 091 for a free, no-obligation review.
Book a Free Consultation