Skip to main content
AD Academy
Microsoft Entra ID (Azure AD)
Intermediate12 minLast updated: Topic 5 of 6

Conditional Access in practice: your first four rules

A baseline rule set to start with, and how to test it without locking everyone out.

Not read

What you will learn here

  • Four Conditional Access rules that fit almost any organization
  • How to test a rule in Report-only mode
  • How to find out why a user was blocked

Worth reading first:PIM made simple: admin rights only when you need them

Conditional Access is “if — then”: if a condition is met, then something is required (MFA, a managed device) or access is blocked. The previous topic covered how a rule is built; here are real rules to start with.

Four rules to start with

  • MFA for all admins — always, from anywhere.
  • MFA for all users — at least outside the corporate network.
  • Block legacy authentication (POP, IMAP, old SMTP AUTH) — it cannot do MFA and is used for password spray.
  • Block sign-ins from countries where the organization has no staff.

Testing without risk

  • Run every new rule in Report-only mode for a week first.
  • In the Sign-in logs, on the Conditional Access tab, you can see what the rule would have done.
  • The What If tool shows which rules apply to a specific user under specific conditions.
  • Always exclude one break-glass account.

Check yourself

Why block legacy authentication?

Was this page helpful?