Conditional Access
13 checks · 3 sub-categories
Conditional Access is where Microsoft 365 stops being a set of on/off switches and becomes a real access-control system: allow or block a sign-in based on who the user is, what device they're on, where they are and how risky the attempt looks. Most tenants we audit have either no Conditional Access at all (relying on Security Defaults) or a handful of half-finished policies left in report-only mode by a previous provider.
Baseline enforcement policies
Legacy authentication blocked
IMAP, POP3, SMTP AUTH and older ActiveSync clients cannot enforce MFA. Attackers target them specifically to walk straight past it. This is consistently one of the highest-impact findings we report.
- Essential Eight — Multi-factor authentication
- CIS 1.1.11
MFA required for all administrators
Verifies a policy actually exists, is enabled (not report-only), targets all privileged roles and has no unexplained exclusions.
- Essential Eight — Multi-factor authentication
MFA required for all users
Checks tenant-wide coverage and enumerates every exclusion group, break-glass account and service identity carved out of it.
- Essential Eight — Multi-factor authentication
Break-glass accounts correctly excluded and monitored
You need at least one emergency-access account that a broken policy cannot lock you out of — and alerting on the day it's ever used.
Risk and location controls
Risky country / geographic access policy
Whether sign-ins from outside your normal operating countries are blocked or challenged. For most Australian SMBs, there is no business reason for a login from another continent.
Risky IP address policy
Blocks or challenges sign-ins from known-malicious or anonymising IP ranges, including Tor and commercial VPN exit nodes.
Named Locations correctly defined
Confirms the trusted office IP ranges and country lists underpinning your other policies are accurate and not still pointing at an old office.
Sign-in risk and user risk policies
Where Entra ID P2 licensing exists, checks that Identity Protection risk signals actually trigger a block or a forced password change.
Sign-in frequency and persistent browser session controls
Prevents an indefinitely valid session token on an unmanaged device from becoming a permanent back door.
Policy quality
Device compliance requirement
Whether access to company data requires a compliant or hybrid-joined device, rather than any browser on any machine anywhere.
- Essential Eight — Restrict administrative privileges
Coverage gap analysis
We map every existing policy against the controls it should be enforcing, so you can see duplicates, orphaned policies and gaps rather than a raw policy dump.
Report-only policies left unenforced
Policies sitting in report-only mode look protective in the admin centre and enforce nothing. We identify each one.
Third-party MFA integration validated
For tenants using Duo or a similar provider, confirms the grant control is genuinely wired into the policy set.
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.