Conditional Access is “if — then”: if a condition is met, then something is required (MFA, a managed device) or access is blocked. The previous topic covered how a rule is built; here are real rules to start with.
Four rules to start with
- MFA for all admins — always, from anywhere.
- MFA for all users — at least outside the corporate network.
- Block legacy authentication (POP, IMAP, old SMTP AUTH) — it cannot do MFA and is used for password spray.
- Block sign-ins from countries where the organization has no staff.
Testing without risk
- Run every new rule in Report-only mode for a week first.
- In the Sign-in logs, on the Conditional Access tab, you can see what the rule would have done.
- The What If tool shows which rules apply to a specific user under specific conditions.
- Always exclude one break-glass account.