Entra ID Conditional Access hardening
Baseline audit found overlapping policies, unblocked legacy auth, and no risk-based signals. Rebuilt CA around a Zero-Trust posture, cut risky sign-ins 42% in 30 days, killed legacy auth entirely.
Overview
Sign-in risk · last 30 days
Risky sign-ins
47 / 1284
Blocked by CA
45 (95.7%)
| Policy | State | Users |
|---|---|---|
| Require MFA for all users | On | All |
| Block legacy authentication | On | All |
| Require compliant device — admins | On | Admins |
| Block risky sign-ins ≥ Medium | On | All |
| Require MFA · guest access | Report | Guests |
Risky sign-ins
-42%
Legacy auth
0
Impossible travel
3/3
Help-desk CA tickets
-58%
Reduce identity attack surface for a 300-seat client while keeping legitimate users productive.
User
Location
Device
Target app
Triggered by: CA-11 · Contractors require MFA + compliant device
Policy chain
- CA-01 · Block legacy authentication
- CA-02 · Block sign-in from TOR / anonymizers
- CA-03 · Geo-restrict to US / CA
- CA-04 · Admin portal requires compliant device
- CA-05 · Service accounts locked to corp network
- CA-10 · Executives require MFA every session
- CA-11 · Contractors require MFA + compliant device
- CA-20 · Baseline MFA for unmanaged devices
Tools
- Entra ID logs
- Microsoft Sentinel
- KQL
- Defender for Cloud Apps
Platforms
- Entra ID
- Microsoft 365
- Sentinel
- 01
Exported current CA via Graph; mapped overlaps and gaps against a Zero-Trust reference.
- 02
Built a policy layer cake: baseline MFA → block legacy auth → compliant device for admins → geo restriction → sign-in-risk gate.
Fig · 02 · Policy detail · report-only rolloutLIVEEntra · Conditional Access · New policyReport-onlyAssignments
Users All users · except break-glass Cloud apps All cloud apps Conditions Sign-in risk: Medium, High Access controls
Grant Require MFA + compliant device Session Sign-in frequency: 4h Persistent browser Never State
Policy Report-only Impact (7d) 142 sign-ins matched Would block 38 · 0 false positives - 03
Staged rollout with report-only + pilot ring of 25 to catch service accounts.
Fig · 03 · Impossible travel · session revokedLIVEAlert · Impossible travela.patel@integris.comDistance
9,821 km
Δ time
31 minutes
Required speed
19,000 km/h (impossible)
Response
Session revoked · MFA re-challenge
42% drop in risky sign-ins, zero legacy-auth events, three impossible-travel alerts triaged clean.
- Report-only mode always catches the service accounts nobody documented.
- Right metric: risky sign-ins per user per week, not raw sign-in counts.
Next case · VULN-007
60-day CVE remediation program with Nessus
Open →
