Conditional Access
Conditional Access is a Microsoft Entra ID feature that enforces access policies using if-then rules combining signals such as user, device, location, and risk with controls like requiring MFA.
Conditional Access is a Microsoft Entra ID feature that evaluates real-time signals — user identity, device compliance state, location, and sign-in risk — and applies if-then policy rules to access requests before granting entry to Microsoft 365 apps, including Copilot experiences. A matching policy can grant access, require multifactor authentication, demand a compliant or Entra hybrid-joined device, or block entirely. A common exam trap is treating MFA as a competing feature: MFA is one grant control it can enforce. Policies are configured in the Microsoft Entra admin center and fire at the authentication layer before any app loads.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →