Skip to main content

Conditional Access

Identity and Access Control

Design Conditional Access as the policy engine for Zero Trust and Copilot-ready Microsoft 365

Conditional Access decides who can access what, from where, on which device and under which risk. A good design protects users and data without locking out business-critical work.

Executive Summary​

Microsoft Entra Conditional Access is the policy enforcement engine of Microsoft's Zero Trust architecture. It evaluates user identity, device posture, location, application, risk signals and session context before granting access to corporate resources.

This document provides an enterprise design methodology for Microsoft 365, Azure, Security and Copilot deployments.

한국어 요약​

Conditional Access는 Microsoft Entra ID 기반의 접근 제어 정책 엔진입니다. 사용자가 누구인지, 어떤 device에서 접속하는지, 어떤 location인지, 어떤 application에 접근하는지, risk signal이 있는지에 따라 접근을 허용하거나 차단합니다.

실무에서는 모든 사용자를 한 번에 차단하는 방식보다 report-only, pilot group, exclusion, break-glass account, sign-in log 분석을 통해 단계적으로 적용하는 것이 안전합니다.

Copilot 도입 시에도 Conditional Access는 중요합니다. Copilot은 Microsoft 365 data permission을 기반으로 동작하므로, identity, device, session, data protection 정책이 함께 정리되어야 합니다.

Why Conditional Access Matters​

CredentialCredential theftRequire MFA, sign-in risk controls and strong authentication for risky access.
SessionSession hijacking and token replayUse risk signals, session controls and device conditions where appropriate.
LegacyLegacy authentication abuseBlock protocols that cannot satisfy modern authentication and MFA requirements.
DeviceUnmanaged device accessRequire compliant or managed devices for sensitive workloads and admin access.
LocationUnexpected location or networkUse named locations, country rules and trusted network logic carefully.
AICopilot data exposure riskAlign Copilot readiness with permission hygiene, device posture and session controls.

Zero Trust Evaluation Flow​

01UserUser, group, role, guest status and privileged access context.
02DeviceRegistered, hybrid joined, Entra joined, Intune compliant or unmanaged.
03ContextLocation, application, platform, client app, risk and session state.
04PolicyConditional Access evaluates conditions, exclusions and grant controls.
05ControlRequire MFA, compliant device, app protection, session control or block access.
06AccessAccess is granted, limited, monitored or blocked with audit evidence.

Policy Layer Model​

Layer 1Baseline MFARequire MFA for users, exclude emergency access accounts and validate user impact.
Layer 2Admin protectionApply stricter controls to privileged roles, admin portals and management workloads.
Layer 3Legacy authentication blockBlock POP, IMAP, SMTP AUTH, Basic Authentication and unsupported clients where applicable.
Layer 4Device and app controlRequire compliant devices, approved apps or app protection for sensitive workloads.
Layer 5Risk and session controlUse user risk, sign-in risk, Defender device risk, app-enforced restrictions and session controls.
Layer 6Workload-specific policiesApply tailored controls for Exchange, SharePoint, Teams, OneDrive, Azure and Copilot scenarios.
MFARequire MFA for all usersScope all users, exclude emergency access accounts and monitor report-only impact first.LegacyBlock legacy authenticationBlock protocols and clients that bypass modern authentication controls.DeviceRequire compliant deviceApply to Exchange, SharePoint, Teams and OneDrive after device readiness is validated.AdminProtect administrative accountsRequire MFA, compliant device, trusted location and stronger session controls for privileged roles.DataRestrict unmanaged device downloadsUse app-enforced restrictions and session controls for sensitive SharePoint and OneDrive access.CopilotControl Copilot accessAlign Copilot pilot groups, device posture, data permission and session policies.

Deployment Journey​

DesignPolicy matrixDefine user scope, application, condition, control, exclusion, owner and validation method.
SimulateReport-only modeRun policy in report-only mode and review sign-in logs before enforcement.
PilotControlled pilot groupApply to pilot users, admin roles or selected workloads with support readiness.
EnforceStaged rolloutExpand by group, workload or risk level, then monitor support tickets and sign-in failures.

Exception and Lockout Control​

Copilot Access Control​

Copilot access control should not be designed as a standalone AI policy. It should inherit the Microsoft 365 access baseline while adding AI-specific readiness checks.

IdentityPilot group and role scopeStart with selected Copilot users, privileged roles and business scenarios.
DeviceCompliant or managed deviceReview whether Copilot access should require managed devices for sensitive roles.
SessionSession and download restrictionsAlign SharePoint, OneDrive and Teams access restrictions with Copilot data exposure risk.
DataPermission hygieneConditional Access does not fix oversharing. Review data permissions and information architecture.
RiskRisk-based controlsUse user risk, sign-in risk and device risk signals for sensitive access paths.
AdoptionUser guidanceExplain why access controls exist so adoption does not become a support problem.

Common Mistakes​

ScopeApplying broad policies too quicklyUse report-only and pilot scope before organization-wide enforcement.
ExclusionsPermanent broad exclusionsEvery exclusion should have owner, reason, expiry and compensating control.
AdminNot separating admin policiesPrivileged roles need stronger controls and different monitoring than standard users.
DeviceRequiring compliance before readinessConfirm Intune enrollment, device inventory and support path before enforcing device controls.
CommunicationNo user communicationRestrictive policies without explanation create support load and user resistance.
CopilotTreating Copilot as only a license issueCopilot readiness also needs identity, device, data and session control alignment.

Search Keywords​

  • Microsoft Entra Conditional Access
  • Conditional Access design
  • Conditional Access policy matrix
  • MFA enforcement
  • compliant device policy
  • Zero Trust access control
  • Copilot access control
  • Conditional Access report-only
  • Conditional Access break glass account
  • Entra ID 보안 정책
  • Conditional Access 컨설팅

Contact / Asset Request​

For Conditional Access policy matrices, report-only rollout checklists, exception registers or Copilot access-control templates, use Contact and Asset Request.