← SC-300: identity, access, and operations
04 / 11 · 35 MIN

Conditional Access and risk

Evaluate the policy set and deployment impact.

Concept and mechanism

Conditional Access combines signals, assignments, and controls. Several policies can apply to one sign-in, and every applicable policy must be satisfied. Requiring MFA in one policy and compliance in another does not let users freely choose one. Alternatives within a configured control do not turn the full set into a first-match engine. In report-only, results help evaluate what would happen without enforcing those requirements as blocking. Failure in that mode does not prove sign-in denial. It also does not mean total absence of effects: compliance checks can cause certificate-selection prompts on certain platforms. Interpret mode and result per policy before concluding that access was protected or interrupted.

Guided application

In a fictional rollout, retain the tested configuration and represented populations. Adding a policy after the pilot changes the evidence needed for expansion. Include support accounts, partners, working devices, and administrative recovery. ID Protection adds risk signals requiring contextual investigation; an authorized location change can explain part of a signal without validating the entire session. Global Secure Access adds identity-centered network-access capabilities: Private Access concerns private resources; Internet Access concerns Internet and SaaS. Confirm clients, connectors, and covered traffic before promising coverage. Close deployment when results demonstrate agreed criteria and RUN can diagnose policies, dependencies, and authorized exceptions.

IN PRACTICE

A new device policy makes an earlier MFA-only pilot insufficient.

Common pitfalls

First-match across policies; report-only as blocking; report-only as zero interaction; risk as proven compromise.

Related topics: Tenant, scope, and objects · Hybrid identity and partners · Methods and emergency access

Take this idea with you

Test the effective policy combination with representative users and paths.

Create account

Reference: Build Conditional Access policies · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately