Identity & Access

A Conditional Access Baseline for Azure in 2026

The minimum viable Conditional Access policy set that stops 95% of identity attacks — with Entra ID configuration details.

RAZR Advisory

7 min read

The baseline

Every Entra ID tenant should ship with these five policies on day one:

  1. Block legacy authentication — no exceptions.
  2. Require MFA for all users — phishing-resistant where possible (FIDO2, Windows Hello).
  3. Require compliant device for admins — Intune-managed, encrypted, patched.
  4. Block sign-ins from unsupported countries — geo-fence by business need.
  5. Require MFA for risky sign-ins — driven by Identity Protection risk score.

Why phishing-resistant MFA matters

SMS and app-push MFA are bypassed daily by attacker-in-the-middle kits like Evilginx. FIDO2 security keys and passkeys are cryptographically bound to the origin — they cannot be phished.

Rollout playbook

  • Start in report-only mode for 2 weeks
  • Review sign-in logs for false positives
  • Enable for pilot group
  • Roll out tenant-wide with named-user exclusion for break-glass accounts
Share this post

Get new posts in your inbox

Field notes on cloud security, compliance, and incident response. One email when we publish. No spam.

Every email includes a one-click unsubscribe link. You can also manage your preferences anytime from the link in the email footer.

Ready to see how your stack scores?

Take the 15-minute diagnostic and get a prioritized 30/60/90-day action plan.

Related posts

More reading based on this post's category and tags.