Knowledge · Identity & Security

Conditional Access for SMEs: The baseline policies

Përparim Kastrati · Updated October 8, 2026

Most successful attacks on Microsoft 365 start with a stolen password. Conditional Access is the tool in Microsoft Entra ID that lets you define the conditions under which a sign-in is allowed: for example, only with MFA, only from managed devices or not from certain countries.

Prerequisites

  • License: Conditional Access requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium as well as in E3 and E5. Risk-based policies require Entra ID P2.
  • Security defaults are the free alternative without P1. They enforce MFA but cannot be customized. Conditional Access and security defaults are mutually exclusive.
  • Two emergency access accounts (break-glass): cloud-only, excluded from all policies, protected with strong authentication (e.g. FIDO2 security keys) and monitored. Without them, a single mistake can lock you out of your own tenant.

The baseline policies

  1. MFA for all users, except the emergency access accounts.
  2. Block legacy authentication: Older protocols such as POP, IMAP or SMTP AUTH cannot do MFA. Microsoft has largely turned them off in Exchange Online; the policy closes the remaining gaps.
  3. Strong MFA for administrators: ideally phishing-resistant (FIDO2, Windows Hello for Business), enforced through authentication strengths.
  4. MFA for admin portals: access to Azure, Entra and the Microsoft 365 admin center only with MFA.
  5. Block device code flow: This sign-in method is increasingly abused for phishing. Microsoft recommends blocking it as far as possible. Exceptions are only needed for devices without a browser, such as Teams Rooms consoles, and should be scoped to a specific group.
  6. Protect security info registration: Allow MFA methods to be added only from trusted locations or with existing MFA. That way, an attacker with a stolen password cannot register their own MFA method.
  7. Managed devices for sensitive access: e.g. access to SharePoint and admin portals only from compliant Intune devices.
  8. Restrict countries: Block sign-ins from countries where no one in your organization works.

Entra ID P2 adds risk-based policies: require MFA for suspicious sign-ins and force a password change for compromised accounts.

How to roll out the policies without outages

  • Enable each policy in Report-only mode first and evaluate the sign-in logs for a few days.
  • Use the What If tool to check which policies apply to a specific user.
  • Manage exclusions through groups, not individual users, and review them regularly.
  • Only then switch the policy to On, ideally step by step, one group at a time.