Conditional Access Policy
An Entra ID feature that enforces access rules based on signals like user location, device compliance, and risk level, requiring conditions such as MFA or blocking sign-in entirely when those conditions aren't met.
Conditional Access Policy
Conditional Access lets you say "require MFA when signing in from outside India" or "block sign-in from non-compliant devices" — access decisions based on real-time context, not just a password.
Why It Matters in Production
PhonePe requires MFA plus a compliant, company-managed device for any admin accessing the production Azure Portal, blocking sign-in attempts entirely from unmanaged personal laptops.
az rest --method POST --uri "https://graph.microsoft.com/v1.0/identity/conditionalAccess/policies" \ --body @ca-policy-require-mfa.jsonSecurityAlways test new Conditional Access policies in "Report-only" mode first — a misconfigured policy can lock out your entire admin team simultaneously.
Frequently Asked Questions
How is a Conditional Access Policy different from a basic MFA requirement?
A blanket MFA requirement applies the same challenge to every sign-in regardless of context. Conditional Access instead evaluates signals — is the sign-in coming from an unfamiliar country, is the device marked compliant in Intune, does Identity Protection flag the sign-in as risky — and applies a policy conditionally based on that combination, ranging from requiring MFA only when risk is elevated to blocking sign-in entirely from disallowed locations or non-compliant devices.
What's a common Conditional Access misconfiguration?
Creating a policy that locks out administrators along with everyone else, with no emergency break-glass account excluded from the policy — a real risk if a policy is misconfigured or a trusted location definition changes unexpectedly. Microsoft explicitly recommends maintaining at least two break-glass accounts excluded from Conditional Access policies, with strong non-MFA-dependent authentication, specifically to avoid a full tenant lockout scenario.