Configuring Conditional Access
This recipe shows how to switch from Security defaults to Conditional Access and configure Conditional Access policies. As three example policies, we will perform the following configurations:
- All users can access an Azure AD-integrated application only when they perform MFA.
- All users can access any Azure AD-integrated applications only when they use a hybrid Azure AD-joined device when they are visiting sensitive countries on business trips.
- No users can use legacy authentication.
Getting ready
To complete this recipe, sign in to the Azure AD tenant with an account that has the Global administrator or Conditional Access administrator role assigned to it. If the organization uses the Azure AD PIM feature, activate the Global administrator or Conditional Access administrator role in advance.
The Conditional Access functionality requires Azure AD Premium P1 licenses or Microsoft licenses that include the P1 license, such as...