GlossarySecurity awareness

Conditional access

Short answer

Conditional access is a set of policies that decide, at each sign in, whether to allow access, require extra verification or block it, based on signals such as who the user is, the device and its security status, the location and the risk of the session. It is a core building block of Zero Trust.

How it works

The identity provider evaluates each access request against rules. If a user signs in from a managed, up to date laptop in the usual country, access is granted. If the same user signs in from an unknown device or an unusual location, MFA is required. If the device is not compliant or the sign in risk is high, access is blocked or limited to a browser session without downloads.

Common policies

Require MFA for all users and stronger methods, such as passkeys, for administrators. Block legacy authentication protocols that cannot do MFA. Allow access to sensitive applications only from managed devices enrolled in MDM. Block sign ins from countries where the company does not operate. Shorten session lifetimes for high risk applications.

Where it is configured

Usually in the identity provider used for SSO, such as Microsoft Entra ID, Google Workspace or Okta. Putting all business applications behind SSO is what makes conditional access cover them.

Doing it safely

Start in report only mode to see the impact before enforcing, keep at least one emergency access account excluded and well protected, and review policies after changes in the organisation. Conditional access is one of the most effective ways to put Zero Trust and least privilege into practice, and it reduces the impact of account takeover.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub