Conditional Access for SMEs: The baseline policies
Most successful attacks on Microsoft 365 start with a stolen password. Conditional Access is the tool in Microsoft Entra ID that lets you define the conditions under which a sign-in is allowed: for example, only with MFA, only from managed devices or not from certain countries.
Prerequisites
- License: Conditional Access requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium as well as in E3 and E5. Risk-based policies require Entra ID P2.
- Security defaults are the free alternative without P1. They enforce MFA but cannot be customized. Conditional Access and security defaults are mutually exclusive.
- Two emergency access accounts (break-glass): cloud-only, excluded from all policies, protected with strong authentication (e.g. FIDO2 security keys) and monitored. Without them, a single mistake can lock you out of your own tenant.
The baseline policies
- MFA for all users, except the emergency access accounts.
- Block legacy authentication: Older protocols such as POP, IMAP or SMTP AUTH cannot do MFA. Microsoft has largely turned them off in Exchange Online; the policy closes the remaining gaps.
- Strong MFA for administrators: ideally phishing-resistant (FIDO2, Windows Hello for Business), enforced through authentication strengths.
- MFA for admin portals: access to Azure, Entra and the Microsoft 365 admin center only with MFA.
- Block device code flow: This sign-in method is increasingly abused for phishing. Microsoft recommends blocking it as far as possible. Exceptions are only needed for devices without a browser, such as Teams Rooms consoles, and should be scoped to a specific group.
- Protect security info registration: Allow MFA methods to be added only from trusted locations or with existing MFA. That way, an attacker with a stolen password cannot register their own MFA method.
- Managed devices for sensitive access: e.g. access to SharePoint and admin portals only from compliant Intune devices.
- Restrict countries: Block sign-ins from countries where no one in your organization works.
Entra ID P2 adds risk-based policies: require MFA for suspicious sign-ins and force a password change for compromised accounts.
How to roll out the policies without outages
- Enable each policy in Report-only mode first and evaluate the sign-in logs for a few days.
- Use the What If tool to check which policies apply to a specific user.
- Manage exclusions through groups, not individual users, and review them regularly.
- Only then switch the policy to On, ideally step by step, one group at a time.