Active
--:--:-- UTCSyed Dayaan Shah
← Back to case filesCase · IAM-014
Identity SecuritySeverity · high3-week rollout

Entra ID Conditional Access hardening

Baseline audit found overlapping policies, unblocked legacy auth, and no risk-based signals. Rebuilt CA around a Zero-Trust posture, cut risky sign-ins 42% in 30 days, killed legacy auth entirely.

Evidence · CA overview · policies + risk trendLIVE
Microsoft Entra · Conditional Access

Overview

Sign-in risk · last 30 days

47

Risky sign-ins

47 / 1284

Blocked by CA

45 (95.7%)

PolicyStateUsers
Require MFA for all usersOnAll
Block legacy authenticationOnAll
Require compliant device — adminsOnAdmins
Block risky sign-ins ≥ MediumOnAll
Require MFA · guest accessReportGuests

Risky sign-ins

-42%

Legacy auth

0

Impossible travel

3/3

Help-desk CA tickets

-58%

[01]Objective

Reduce identity attack surface for a 300-seat client while keeping legitimate users productive.

[02]Live Lab · Conditional Access policy simulator
Interactive · runs in your browser

User

Location

Device

Target app

DecisionBLOCK

Triggered by: CA-11 · Contractors require MFA + compliant device

Policy chain

  • CA-01 · Block legacy authentication
  • CA-02 · Block sign-in from TOR / anonymizers
  • CA-03 · Geo-restrict to US / CA
  • CA-04 · Admin portal requires compliant device
  • CA-05 · Service accounts locked to corp network
  • CA-10 · Executives require MFA every session
  • CA-11 · Contractors require MFA + compliant device
  • CA-20 · Baseline MFA for unmanaged devices
[03]Stack · Tools & Platforms

Tools

  • Entra ID logs
  • Microsoft Sentinel
  • KQL
  • Defender for Cloud Apps

Platforms

  • Entra ID
  • Microsoft 365
  • Sentinel
[04]Method
  1. 01

    Exported current CA via Graph; mapped overlaps and gaps against a Zero-Trust reference.

  2. 02

    Built a policy layer cake: baseline MFA → block legacy auth → compliant device for admins → geo restriction → sign-in-risk gate.

    Fig · 02 · Policy detail · report-only rolloutLIVE
    Entra · Conditional Access · New policyReport-only

    Assignments

    UsersAll users · except break-glass
    Cloud appsAll cloud apps
    ConditionsSign-in risk: Medium, High

    Access controls

    GrantRequire MFA + compliant device
    SessionSign-in frequency: 4h
    Persistent browserNever

    State

    PolicyReport-only
    Impact (7d)142 sign-ins matched
    Would block38 · 0 false positives
  3. 03

    Staged rollout with report-only + pilot ring of 25 to catch service accounts.

    Fig · 03 · Impossible travel · session revokedLIVE
    Alert · Impossible travela.patel@integris.com
    Houston, TX · 09:41 UTCBucharest, RO · 10:12 UTC

    Distance

    9,821 km

    Δ time

    31 minutes

    Required speed

    19,000 km/h (impossible)

    Response

    Session revoked · MFA re-challenge

[05]Outcome

42% drop in risky sign-ins, zero legacy-auth events, three impossible-travel alerts triaged clean.

[06]Lessons learned
  • Report-only mode always catches the service accounts nobody documented.
  • Right metric: risky sign-ins per user per week, not raw sign-in counts.

Next case · VULN-007

60-day CVE remediation program with Nessus

Open →