Conditional Access: the rulebook that decides when Microsoft asks for MFA
Conditional Access is the rulebook that decides when Microsoft 365 asks for a second check. What it is, whether you have it, and the baseline to ask for.
Somewhere on your cyber-insurance renewal there's a checkbox: "Is multi-factor authentication enforced for all users?" Most owners tick yes and move on. But in Microsoft 365, "enforced" isn't one switch. It's a set of rules called Conditional Access — and whether that box is honestly a yes depends on how those rules are written.
Here's the plain-English version of what your IT provider means when they say it, and the three things worth checking.
The bouncer at the door
Every time someone signs in to Microsoft 365, a rulebook decides in that moment what happens next. Microsoft's own definition is refreshingly simple: Conditional Access policies are if-then statements. If a user wants to access something, then they must meet a condition.
The rules can look at who is signing in, from where, on what device, and into which app — and then decide: let them in, ask for a second check (multi-factor authentication, or MFA — the code or app tap after your password), or block the attempt entirely.
Think of it as a bouncer with a checklist. The bouncer is only as good as the checklist.
First question: do you have it at all?
Microsoft 365 has two different bouncers, and most small businesses have never been told which one they're using.
Security defaults is the free, preset bundle. Everyone registers for MFA, Microsoft decides when to prompt for it, and older sign-in methods that can't do MFA are blocked. There are no settings to adjust — it's on or off. Most Microsoft 365 setups created since late 2019 started with it on, and for a small team it's a solid baseline: Microsoft says MFA plus blocking those legacy sign-in methods stops more than 99.9% of common identity attacks.
Conditional Access is the custom rulebook. It comes with Microsoft 365 Business Premium (or as an add-on license called Entra ID P1) and lets your IT provider write precise rules. Here's the catch: to use it, security defaults gets switched off. From that moment, the custom rules are the only bouncer working the door — so they have to be written right.
If you have an IT provider and Business Premium, you're probably on Conditional Access. That's where the checking begins.
Three phrases that decide whether your MFA is real
"All users, all apps." A policy only protects who and what it covers. A rule that requires MFA for admins doesn't cover your bookkeeper. A rule that covers email doesn't cover the dozen other ways to sign in to your Microsoft account. Scope gaps like these are the most common way businesses that "have MFA" still lose accounts — the attacker walks in through a door the rule never mentioned.
"Report-only." Every policy has a state: on, off, or report-only. Report-only means the rule is evaluated and logged but not enforced — nobody is actually prompted for anything. It's a sensible way to test a new rule for a week. It's a quiet disaster when the MFA policy has been sitting there for a year and everyone assumes it's working.
"Trusted locations." Rules can be told to skip checks for sign-ins from the office network. Convenient — and it means anyone who gets onto your office Wi-Fi, or into one office computer, skips them too. Not automatically wrong, but you should know if you have one and why.
The baseline worth asking for by name
When Microsoft moves organizations off security defaults, it offers Microsoft-managed policies that keep the same protections. That's a good shorthand for the minimum a small-business rulebook should contain:
- Require MFA for all users
- Require MFA for admins
- Block legacy authentication (the old sign-in methods that can't do MFA)
- Require MFA for admin tools and Azure management
This week
- Ask which bouncer you have. One-sentence email to your IT provider: "Are we on security defaults or Conditional Access?" Two minutes.
- If it's Conditional Access, ask for the policy list. A screenshot is enough. Look at two things: is each policy On (not report-only), and does the MFA policy say all users and all apps?
- Ask about exceptions. Any trusted locations or excluded accounts? There may be good reasons — you just want them to be decisions, not accidents.
If you'd rather see it than ask: Tenant Strike's read-only scan checks exactly these things — whether MFA is truly enforced for everyone, which policies are stuck in report-only, where the scope gaps are — and turns it into an A–F graded report with the exact fix in under five minutes.
AI-researched from public sources, human-reviewed on July 23, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.