All topics and tags

Conditional Access

21 articles tagged Conditional Access.

  1. AADSTS50076, 50079 and 50158: fix Microsoft Entra MFA sign-in errors

    What AADSTS50076, AADSTS50079 and AADSTS50158 mean, how to find the policy that demanded MFA in the Entra sign-in logs, and how to fix each one for users, scripts and federated domains.

  2. AADSTS53003 blocked by Conditional Access: find the policy and fix it

    Troubleshoot AADSTS53003 in Microsoft Entra ID: trace the correlation ID to the sign-in log, identify the blocking Conditional Access policy, and fix the user, device or policy without weakening security.

  3. Azure point-to-site VPN with Entra ID sign-in, MFA and the Azure VPN Client

    Configure an Azure VPN Gateway point-to-site connection that signs users in with Microsoft Entra ID, enforce MFA, and deploy the Azure VPN Client profile with Intune.

  4. Block legacy authentication in Microsoft 365 without breaking printers

    Find every device and app that still signs in with legacy authentication, move printers and scanners to a supported sending method, then block legacy auth with Conditional Access.

  5. Break-glass accounts in Entra ID: a lockout-proof Conditional Access setup

    Create two emergency access accounts in Microsoft Entra ID, protect them with FIDO2 passkeys, exclude them safely from Conditional Access, and alert on every sign-in with Azure Monitor.

  6. Conditional Access All resources exclusions: test the 2026 change

    Since June 2026, Conditional Access enforces All resources policies with exclusions on sign-ins that request only baseline scopes. Find the affected apps, test them and choose an enforcement setting.

  7. Conditional Access for AI agents: secure Entra Agent ID sign-ins

    Apply Conditional Access to AI agents in Microsoft Entra: block unapproved and risky agent identities, protect agent user accounts, and keep on-behalf-of access covered by user policies.

  8. Conditional Access token protection: stop stolen token replay

    Bind Microsoft 365 sign-in sessions to the device with Conditional Access token protection: supported apps, report-only rollout, sign-in log status codes, KQL and exclusions.

  9. Configure Entra certificate-based authentication with smart cards and PKI

    Set up native Microsoft Entra certificate-based authentication: upload your PKI, publish reachable CRLs, bind certificates to users and enforce CBA as phishing-resistant MFA.

  10. Entra cross-tenant access settings: trust partner MFA, devices and apps

    Configure Microsoft Entra cross-tenant access settings for a partner: scope inbound and outbound B2B access, trust their MFA and device claims, and enforce Conditional Access for partner users.

  11. Govern Copilot Studio Agents with Microsoft Entra Agent ID Identities

    Find the Entra Agent ID behind each Copilot Studio agent, review its connector permissions, migrate legacy app registrations and apply Conditional Access.

    AI engineering16 min read
  12. Migrate legacy Entra ID Protection risk policies to Conditional Access

    The legacy user risk and sign-in risk policies in Entra ID Protection reached their 1 October 2026 retirement date. Rebuild them in Conditional Access, test in report-only and switch them on.

  13. Plan a Microsoft 365 MFA rollout with Conditional Access and Authenticator

    A phased plan to require MFA for every Microsoft 365 user: pick security defaults or Conditional Access, set authentication methods, drive registration, pilot in report-only mode, then enforce.

  14. Replace Conditional Access custom controls with external MFA in Entra ID

    Conditional Access custom controls are frozen and retire in 2027. Move Duo or another third-party MFA provider to external MFA, switch policies to the MFA grant and remove the custom control.

  15. Replace Require Approved Client App with the App Protection Policy Grant

    Policies using the retired approved client app grant are now read-only. Find them, build replacements that require an app protection policy, test in report-only and cut over.

  16. Require compliant devices for Microsoft 365 with Conditional Access

    Build Intune compliance policies for Windows and iOS, mark unassigned devices noncompliant, then require a compliant device in Conditional Access without locking users out.

  17. Require phishing-resistant MFA for admins with authentication strengths

    Use Conditional Access authentication strengths to require passkeys (FIDO2), Windows Hello for Business or certificate-based authentication for Microsoft Entra admin roles, including PIM activation.

  18. Restore deleted Conditional Access policies with Entra Backup and Recovery

    Recover deleted or misconfigured Conditional Access policies, named locations and other Entra objects using soft delete, difference reports and targeted recovery jobs in Microsoft Entra Backup and Recovery.

  19. Set up Entra Privileged Identity Management for just-in-time admin roles

    Replace standing admin access with eligible role assignments in Microsoft Entra PIM: inventory current admins, configure role settings, assign, activate, and monitor Entra and Azure roles.

  20. Troubleshoot Conditional Access with the What If tool and sign-in logs

    Find out why a Conditional Access policy did or did not apply to a sign-in by reading the sign-in log, simulating it with What If, and querying results at scale.

  21. Decommissioning Legacy VPNs: A Zero-Trust Remote Access Architecture for the Enterprise

    A reference architecture for replacing castle-and-moat VPN perimeters with identity-centric Zero Trust using Microsoft Entra ID P2, Zscaler Private Access and Continuous Access Evaluation.