Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryConditional Access
Glossary

Conditional Access

Conditional Access is an Entra ID feature that checks each sign-in against user, device, location and risk policies, then allows, blocks or asks for MFA.

Definition

What is Conditional Access?

Conditional Access is the policy engine in Microsoft Entra ID that decides, at every sign-in to Microsoft 365 and connected applications, whether to allow access outright, or to block it or require additional steps such as multi-factor authentication or a compliant device. Each policy pairs conditions (who is signing in, from where, on what device, to which app, with what risk score) with a decision. It is the mechanism through which a business turns security intentions into rules that are enforced automatically.

When a user signs in, Entra ID collects the signals: the user's group memberships, the application requested, the device's registration and compliance state from Intune, the network location, the client app type and, with Entra ID P2, the real-time risk assessment from Identity Protection. Every enabled policy whose conditions match is evaluated, and the controls are combined; if any policy blocks, access is blocked. Typical policies for a small business include requiring MFA for all users, blocking legacy authentication protocols that cannot do MFA, requiring a compliant or hybrid-joined device for access to email and files, blocking sign-ins from countries where the company has no staff, and requiring phishing-resistant MFA for administrators.

Conditional Access is included with Entra ID P1, which comes with Microsoft 365 Business Premium, so most small companies already own it. The common problem is that it is left at defaults or configured once and never revisited, leaving exceptions such as a service account excluded from MFA that an attacker eventually finds. Policies should be built in report-only mode first, then enforced, and reviewed whenever staff or applications change.

NetSys designs and maintains Conditional Access policies for clients as part of its Microsoft 365 security service, following a baseline that requires MFA everywhere, blocks legacy protocols, ties access to Intune-compliant devices and keeps break-glass accounts documented. The policies are reviewed on a schedule rather than set once.

Why it matters for a small business

Conditional Access is where the security settings you have been told to turn on, MFA and device requirements among them, are enforced. Without it those settings depend on each user doing the right thing. With it, a stolen password from a phishing email fails at sign-in because the attacker's device is not enrolled and their location is wrong. You most likely already pay for it in Business Premium. The work is in configuring it carefully so it protects the company without locking out the owner.

Common Questions

Conditional Access: FAQs

Is Conditional Access included in Microsoft 365 Business Premium?

Yes. Business Premium includes Microsoft Entra ID P1, which provides Conditional Access. Business Standard and Business Basic do not; they rely on Security Defaults, a fixed set of rules that requires MFA for everyone but cannot be tailored. Risk-based policies, which react to leaked credentials or impossible-travel sign-ins in real time, need Entra ID P2. For most small businesses, Business Premium plus a P2 license for administrators covers the useful policy set.

What Conditional Access policies should a small business have?

A practical baseline has five parts: require MFA for all users on all cloud apps; block legacy authentication, which cannot do MFA; require a compliant or hybrid-joined device for access to Exchange, SharePoint and Teams; require phishing-resistant MFA and a compliant device for administrators; and restrict or block sign-ins from countries where the business has nobody. Two break-glass accounts, excluded from every policy and monitored, prevent a mistaken policy from locking everyone out. Build each policy in report-only mode first.

What is the difference between Conditional Access and MFA?

MFA is one of the controls Conditional Access can require. Conditional Access is the decision layer that looks at the circumstances of a sign-in and decides which controls apply: MFA, a compliant device, a password change, or an outright block. MFA on its own is a switch that is on or off per user. Conditional Access lets MFA be required in some situations and skipped in others, such as on a managed device in the office, while adding device and location checks that MFA alone does not provide.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.