Controlling when access is permitted.
WHAT THEY DO
Evaluate conditions at sign-in and decide whether to permit, block, or require something additional.
WHAT CONDITIONS CAN BE EVALUATED
Who the user is What application they are reaching What device they are using, and its compliance state Where they are What risk the sign-in presents
WHAT ACTIONS CAN BE REQUIRED
Additional authentication A compliant or managed device Accepting terms Blocking entirely
WHAT TO IMPLEMENT AS A BASELINE
Additional authentication for all users Blocking legacy authentication Additional requirements for administrators
WHAT TO BE EXTREMELY CAREFUL WITH
Locking yourself out.
HOW THAT HAPPENS
A policy applying to all users, including every administrator, with a condition nobody can satisfy.
WHAT PREVENTS IT
Excluding at least one emergency access account from every policy.
WHAT AN EMERGENCY ACCESS ACCOUNT IS
An account with permanent administrative rights, excluded from policies, with credentials stored securely offline.
WHAT TO DO WITH IT
Monitor its use, and never use it routinely.
WHAT TO ALWAYS DO BEFORE ENABLING A POLICY
Run it in report-only mode, and examine what would have been affected.