What Is Conditional Access? A Plain-English Explanation
Conditional Access is how Microsoft Entra ID decides whether to allow a sign-in. Here's what it does, why it matters and how growing businesses typically use it.
By Benicio Hernandez · September 27, 2026 · 5 min read
Conditional Access is a feature of Microsoft Entra ID (formerly Azure AD) that evaluates every sign-in and decides what should happen: allow it, require something extra like multi-factor authentication, or block it.
Think of it as a set of if-then rules for access. If someone signs in to Microsoft 365 from an unmanaged device, then require MFA and limit what they can download. If someone signs in with an administrator account, then require phishing-resistant MFA. If a sign-in comes from a legacy protocol that can't do MFA, then block it.
The building blocks
- Assignments: who the policy applies to (users, groups, roles) and which applications.
- Conditions: context about the sign-in, such as device platform, location, client app and sign-in risk (with appropriate licensing).
- Grant controls: what's required to get in, such as MFA, a compliant device, or a specific authentication strength.
- Session controls: limits after sign-in, such as sign-in frequency or restricting downloads in the browser.
Policies most growing companies start with
- Require MFA for all users.
- Require stronger MFA for administrative roles.
- Block legacy authentication.
- Require a compliant or managed device for access to sensitive apps (works with Intune).
- Restrict or add controls for sign-ins from countries you don't operate in.
Licensing
Conditional Access requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium and several enterprise plans. Companies without it can still turn on Security Defaults, a simpler baseline that enforces MFA but can't be customised.
Why it matters
Most account compromises start with a stolen or guessed password. Conditional Access means a password alone isn't enough, and it lets you tie access to managed, healthy devices. Well-designed policies are one of the highest-impact security improvements a Microsoft 365 company can make.