← Microsoft 365 audit scope

Conditional Access

13 checks · 3 sub-categories

Conditional Access is where Microsoft 365 stops being a set of on/off switches and becomes a real access-control system: allow or block a sign-in based on who the user is, what device they're on, where they are and how risky the attempt looks. Most tenants we audit have either no Conditional Access at all (relying on Security Defaults) or a handful of half-finished policies left in report-only mode by a previous provider.

Baseline enforcement policies

  • Legacy authentication blocked

    IMAP, POP3, SMTP AUTH and older ActiveSync clients cannot enforce MFA. Attackers target them specifically to walk straight past it. This is consistently one of the highest-impact findings we report.

    • Essential Eight — Multi-factor authentication
    • CIS 1.1.11
  • MFA required for all administrators

    Verifies a policy actually exists, is enabled (not report-only), targets all privileged roles and has no unexplained exclusions.

    • Essential Eight — Multi-factor authentication
  • MFA required for all users

    Checks tenant-wide coverage and enumerates every exclusion group, break-glass account and service identity carved out of it.

    • Essential Eight — Multi-factor authentication
  • Break-glass accounts correctly excluded and monitored

    You need at least one emergency-access account that a broken policy cannot lock you out of — and alerting on the day it's ever used.

Risk and location controls

  • Risky country / geographic access policy

    Whether sign-ins from outside your normal operating countries are blocked or challenged. For most Australian SMBs, there is no business reason for a login from another continent.

  • Risky IP address policy

    Blocks or challenges sign-ins from known-malicious or anonymising IP ranges, including Tor and commercial VPN exit nodes.

  • Named Locations correctly defined

    Confirms the trusted office IP ranges and country lists underpinning your other policies are accurate and not still pointing at an old office.

  • Sign-in risk and user risk policies

    Where Entra ID P2 licensing exists, checks that Identity Protection risk signals actually trigger a block or a forced password change.

  • Sign-in frequency and persistent browser session controls

    Prevents an indefinitely valid session token on an unmanaged device from becoming a permanent back door.

Policy quality

  • Device compliance requirement

    Whether access to company data requires a compliant or hybrid-joined device, rather than any browser on any machine anywhere.

    • Essential Eight — Restrict administrative privileges
  • Coverage gap analysis

    We map every existing policy against the controls it should be enforcing, so you can see duplicates, orphaned policies and gaps rather than a raw policy dump.

  • Report-only policies left unenforced

    Policies sitting in report-only mode look protective in the admin centre and enforce nothing. We identify each one.

  • Third-party MFA integration validated

    For tenants using Duo or a similar provider, confirms the grant control is genuinely wired into the policy set.

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.