
Updated September 16, 2026.
Conditional Access decides who gets into your Microsoft 365 the moment someone signs in, and it blocks the logins that look wrong. It checks who the user is, what device they're on, where they're connecting from, and how risky the attempt looks, then allows it, challenges it, or shuts it down. For a small business, that's the difference between a stolen password being a minor annoyance and a full account takeover.
Credentials are the way in. In the 2025 Verizon Data Breach Investigations Report, credential abuse showed up as the initial attack vector in 22% of breaches. A password on its own is not a wall. Conditional Access is how you add the wall.
One thing to flag up front if you already run Microsoft 365: two Entra changes hit between now and early 2027, and the first one is October 1. Skip ahead if that's why you're here.
What is Conditional Access in Microsoft 365?
Conditional Access is a set of if-then rules in Microsoft Entra ID that control access to Microsoft 365. If a sign-in meets your conditions, right user, managed device, expected location, it goes through. If it doesn't, Entra can force a multi-factor prompt, block the login outright, or limit what the session is allowed to do.
Think of it as a bouncer who checks more than the password. The password says "I know the code." Conditional Access asks who's actually holding it, on what, and from where.
Why does a small business need it?
Because attackers buy and phish passwords by the thousand, and small businesses are the easy target. Multi-factor authentication is the single biggest fix here. Microsoft's research found that MFA can block over 99.9% of account compromise attacks.
Conditional Access is what lets you require that MFA intelligently, and go further. You can insist that admin accounts only sign in from managed devices, shut off outdated login methods attackers still exploit, and challenge anything that looks off. It turns "we hope everyone turned on MFA" into "the system won't let them skip it."
What can Conditional Access actually block?
Plenty of the sign-ins that turn into incidents. A few of the common ones:
- Logins from countries you don't operate in
- Sign-ins from unmanaged personal devices reaching sensitive data
- Legacy authentication protocols that can't do MFA
- Risky sign-ins that Entra flags based on behavior and known attack patterns (this one needs a higher tier, see below)
- Access to admin roles without a fresh MFA prompt
Do you need Business Premium for Conditional Access?
Yes, in most cases. Conditional Access requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium. Business Standard doesn't include it. If you're on Standard and care about sign-in security, Premium is the upgrade that pays for itself the first time it stops a takeover.
One caveat: the risk-based policies, the ones that react to a sign-in Entra scores as suspicious, need Entra ID P2 with ID Protection, a step above Business Premium. The device, location, and MFA rules that do most of the work are all covered by P1.
If you're already running those risk policies, read the next section. They're being retired.
Two Conditional Access changes land between now and early 2027
Both need a decision from someone who administers your tenant. Neither happens automatically in your favor.
Legacy risk policies retire October 1, 2026
Microsoft Learn puts it plainly: "The legacy risk policies configured in Microsoft Entra ID Protection will be retired on October 1, 2026."
These are the standalone user-risk and sign-in-risk policies you set inside ID Protection rather than in Conditional Access. If yours still live there, rebuild them as Conditional Access policies before the date.
Microsoft's migration order is the sensible one: create the equivalent risk-based policies in Conditional Access in report-only mode, confirm they behave the way the old ones did, then disable the originals.
Nothing carries over on its own. A tenant that ignores the date keeps paying for the license and loses the enforcement.
Custom controls stop accepting changes in September 2026
Adding new custom controls and editing existing ones ends this month. Microsoft has scheduled "full retirement... for early 2027."
This only matters if you use a third-party MFA provider wired into Conditional Access through a custom control — Duo and similar. The replacement is external MFA, which Microsoft now ships as generally available. Their advice is short: "Start planning your migration now."
If you've never touched custom controls, there's nothing here for you.
Where should a small business start?
Start with a small set of policies and test them before you enforce them. Entra has a report-only mode that shows you what a policy would have done without actually blocking anyone. Use it.
A sensible starter set:
- Require MFA for all users
- Block legacy authentication
- Require a managed or compliant device for admin accounts
- Challenge or block sign-ins from outside the countries you work in
Also set up two break-glass admin accounts that are excluded from the policies, so a misconfigured rule can never lock you out of your own tenant. This is close cousin work to a zero trust approach, and it pairs well with phishing-resistant logins like passkeys.
Getting the policies right, keeping them tuned as your business changes, and catching deadlines like the October 1 retirement before they bite is the part most owners hand off. Our Microsoft 365 management team builds and maintains Conditional Access as part of securing your tenant, and it's one of the first things we check in a Microsoft 365 security review.
Want your Microsoft 365 sign-ins locked down without locking out your team? Contact The NetSys Group for a complimentary security assessment and we'll show you where your tenant stands.
Frequently asked questions
When do Entra ID Protection risk policies retire?
October 1, 2026. Microsoft is retiring the legacy user-risk and sign-in-risk policies configured inside ID Protection, and admins have to rebuild them as risk-based Conditional Access policies. Build the replacements in report-only mode, confirm they match what the old policies did, then disable the originals. Nothing migrates on its own.
Do I need to do anything about Conditional Access custom controls?
Only if you use them. Custom controls are how some tenants wire a third-party MFA provider into Conditional Access. Microsoft stops allowing new ones or edits in September 2026 and retires them fully in early 2027, with external MFA as the replacement. If your MFA is Microsoft's own, there's nothing to migrate.
Is Conditional Access the same as MFA?
No. MFA is one of the actions Conditional Access can require. Conditional Access is the policy engine that decides when to require MFA, when to block a sign-in, and when to limit a session, based on the user, device, location, and risk. MFA is the lock; Conditional Access decides which door needs it.
Will Conditional Access lock out my staff?
Not if you roll it out properly. Test every policy in report-only mode first to see who it would affect, then turn it on. Always keep two break-glass admin accounts excluded from the policies so a bad rule can't lock you out of the tenant.
Does Conditional Access work with personal phones?
Yes. You can require app protection policies that keep company data inside managed apps on a personal phone, or block unmanaged devices from reaching sensitive data entirely. You control the level without having to own the device.
How long does it take to set up?
A starter set of policies takes an afternoon to build and a week or two of report-only testing before you enforce them. Tuning is ongoing, since new apps, roles, and locations change what the rules should allow.
What is legacy authentication and why block it?
Legacy authentication is older sign-in methods, like basic auth in some email clients, that can't enforce MFA. Attackers target them specifically because they bypass your MFA. Blocking legacy auth closes that gap, though you should check first that no critical app still depends on it.
Sources and further reading
- Microsoft Learn — Configure risk policies in Entra ID Protection — the October 1, 2026 retirement date and the migration path into Conditional Access. Accessed September 2026.
- Microsoft Learn — Migrate from custom controls to external MFA — the September 2026 freeze on new and edited custom controls, and full retirement in early 2027. Accessed September 2026.
- Microsoft Learn — Conditional Access overview — the Entra ID P1 licensing requirement. Accessed September 2026.
- Verizon 2025 Data Breach Investigations Report — credential abuse as the initial attack vector in 22% of breaches. Accessed September 2026.
By Latoya Reed, who leads cloud and Microsoft 365 services at The NetSys Group. NetSys has delivered managed IT, cybersecurity, and cloud services since 1998 to businesses across NY, NJ, CT, PA, and Southwest Florida.
Related reading
CybersecurityMicrosoft Secure Score: What's a Good Score for an SMB?
Read Article
CybersecurityNIST Password Guidelines: What Small Businesses Change Now
Read Article
Managed ITMicrosoft Entra ID P1 vs P2: Which Do You Need?
Read ArticleAlso on this topic: Intune Policies for Small Business: A Starting Baseline · Microsoft 365 Security Best Practices: A 9-Point Checklist for Small Businesses
Discuss microsoft 365 management & backup for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
