How it works
The identity provider evaluates each access request against rules. If a user signs in from a managed, up to date laptop in the usual country, access is granted. If the same user signs in from an unknown device or an unusual location, MFA is required. If the device is not compliant or the sign in risk is high, access is blocked or limited to a browser session without downloads.
Common policies
Require MFA for all users and stronger methods, such as passkeys, for administrators. Block legacy authentication protocols that cannot do MFA. Allow access to sensitive applications only from managed devices enrolled in MDM. Block sign ins from countries where the company does not operate. Shorten session lifetimes for high risk applications.
Where it is configured
Usually in the identity provider used for SSO, such as Microsoft Entra ID, Google Workspace or Okta. Putting all business applications behind SSO is what makes conditional access cover them.
Doing it safely
Start in report only mode to see the impact before enforcing, keep at least one emergency access account excluded and well protected, and review policies after changes in the organisation. Conditional access is one of the most effective ways to put Zero Trust and least privilege into practice, and it reduces the impact of account takeover.




