Conditional Access
Last updated
Last updated
Azure AD Conditional Access is a powerful feature that helps organizations manage and secure access to their resources based on specific conditions. It enables granular control over access decisions, ensuring that only authorized users can access certain resources under specific circumstances.
Here are key features:
1. Verify Every Access Attempt
Every user access is assessed in real-time based on context like location, device compliance, and user risk, before granting or denying access.
Access decisions can be made based on conditions:
Allow: Grant access if conditions are met.
Block: Deny access if conditions aren't met.
Require MFA: Enforce multi-factor authentication in high-risk scenarios.
IP Restrictions: Block or allow access based on specific IP addresses.
Service Restrictions: Apply rules to specific services (e.g., requiring MFA for SharePoint access).
Network-Based Restrictions: Limit access to trusted networks.
VPN/Tor Restrictions: Block access from VPNs or Tor circuits to prevent masked or untrusted logins.
This ensures only authorized users can access resources under secure and appropriate conditions.