Microsoft 365 Security

Conditional Access in Microsoft 365: A Guide for UK Businesses

Conditional Access is a Microsoft 365 security feature that controls who can access your business systems, from which devices, locations, and under what conditions — before granting or blocking access. It replaces the outdated model of trusting any u..

Overview

Conditional Access is Microsoft Entra ID's policy engine for controlling access to M365 based on user, device, location, and risk signals. It enforces MFA reliably, blocks legacy authentication, and requires device compliance — replacing the insecure binary credential check. M365 Business Premium includes Entra ID P1, enabling full Conditional Access.

Learn about M365 security

How does Conditional Access work?

Conditional Access sits between a login attempt and the resource behind it. When a user signs in, it reads a set of signals, scores the risk, and enforces an outcome. It replaces the blunt "correct password equals access" model with rules that adapt to context.

A policy has three parts:

  • Assignments — which users, groups, and cloud apps the policy covers (all staff, just finance, just SharePoint).
  • Conditions — the signals it evaluates: sign-in risk, device compliance, location, and client app.
  • Access controls — the result: grant, grant with MFA, require a compliant device, force a password reset, or block outright.

Microsoft's own guidance describes Conditional Access as the heart of its Zero Trust identity model, where every request is verified before access is granted (learn.microsoft.com).

Why do UK SMEs need Conditional Access?

Most successful breaches start with stolen credentials, and a password alone is no longer a control. Conditional Access breaks that attack chain: even with valid credentials, an attacker from an unknown device or country is challenged or blocked before reaching your data.

Phishing remains the dominant route in. According to the UK government's Cyber Security Breaches Survey 2025, 85% of businesses that identified a cyber breach experienced phishing (gov.uk). Conditional Access is the layer that stops a phished credential turning into full tenant access.

For GDPR, it gives you a documented, auditable access-control mechanism that supports the technical security expectations under Article 32 (ico.org.uk). It also supports Cyber Essentials and NCSC access-control guidance (ncsc.gov.uk).

What are the essential Conditional Access policies?

A small, well-scoped baseline covers most of the risk for a UK SME. AMVIA deploys and tests the following as a standard starting set, then tunes them to your user base and device estate.

  • Require MFA for all users — the single highest-impact policy; stops the bulk of credential attacks. Pairs naturally with a managed MFA setup for Microsoft 365.
  • Block legacy authentication — old protocols (IMAP, POP3, SMTP AUTH) cannot do MFA and must be closed off. Test first; some line-of-business apps still rely on them.
  • Require a compliant device for sensitive apps — SharePoint, OneDrive, and finance systems only reachable from devices enrolled and healthy in Microsoft Intune.
  • Block high-risk sign-ins — Entra ID Protection scores each sign-in; high-risk attempts are blocked automatically.
  • Restrict access by country — if no one should ever sign in from a given region, block it. Low maintenance, high return.

These policies sit on top of identity controls in Microsoft Entra ID and work best alongside endpoint protection from Microsoft Defender for Business.

Per-user MFA vs Conditional Access: what's the difference?

Many businesses still run Microsoft's legacy per-user MFA toggle and assume they are covered. Conditional Access is a different class of control: policy-driven, context-aware, and consistent across every app.

CapabilityLegacy per-user MFAConditional Access
MFA enforcementOn or off per accountTriggered by risk, device, or location
Block legacy authenticationNoYes
Device compliance checksNoYes (with Intune)
Risk-based blockingNoYes (with Entra ID Protection)
Geographic restrictionsNoYes (named locations)
Report-only testingNoYes
Minimum licenceAnyEntra ID P1

The takeaway: per-user MFA is better than nothing, but Conditional Access is what an attacker actually has to defeat.

Which Microsoft 365 licence includes Conditional Access?

Conditional Access needs Microsoft Entra ID P1 as a minimum. That licence is bundled into Microsoft 365 Business Premium, M365 E3, M365 E5, and Entra ID P1 standalone. Business Basic and Business Standard do not include it without an add-on.

This is the practical reason AMVIA recommends Business Premium for any UK SME with real security needs. Microsoft Business Premium lists at £16.90 per user per month (ex VAT, annual commitment), and it folds in Conditional Access, Intune, and Defender for Business in one licence (microsoft.com/en-gb). Stepping up from Business Standard at £9.60 is usually cheaper than buying Entra ID P1 separately and stitching it together.

What mistakes do UK businesses make with Conditional Access?

Conditional Access is powerful enough to lock your own people out if it is rushed. The failures we see most often are operational, not technical.

  • Enabling enforcement without testing — always run new policies in report-only mode first, read the sign-in logs, then enforce.
  • No break-glass account — every tenant needs at least two emergency admin accounts excluded from all policies, so a bad rule can be undone.
  • Blanket policies — requiring a compliant device just to send email creates friction with no benefit. Scope each policy to the apps and data that justify it.
  • Ignoring named locations — without defined office IP ranges, the engine cannot tell your Sheffield office from an overseas attacker, and staff get challenged needlessly.

A standalone Microsoft 365 security audit surfaces these gaps before they cause an outage or a breach.

How does AMVIA manage Conditional Access?

Getting Conditional Access right means understanding your users, devices, apps, and compliance obligations — then building policies that are strict on attackers and quiet for staff. Misconfiguration cuts both ways: too loose and you have gaps, too tight and you have outages.

AMVIA's managed Microsoft 365 service includes the full lifecycle:

  • Audit of your current Entra ID and sign-in configuration
  • A policy set designed for your business, not a copied template
  • Report-only testing before any policy is enforced
  • Ongoing monitoring of sign-in logs and policy effectiveness
  • Regular reviews as your team, devices, and apps change
  • Integration with Intune so device compliance drives access decisions

This is part of the wider managed cybersecurity practice that makes identity, endpoint, and email security one accountable service rather than three disconnected tools.

Key Points

What UK businesses need to know about Conditional Access.

Enforces MFA Correctly

Conditional Access enforces MFA reliably across all applications — unlike per-user MFA settings which can be inconsistently applied or bypassed.

Blocks Legacy Authentication

Legacy protocols like IMAP and SMTP AUTH do not support MFA. Conditional Access can block these entirely — eliminating one of the most common attack vectors.

Requires Device Compliance

Policies can require devices to be enrolled in Intune and compliant with MDM policies before accessing sensitive applications.

Risk-Based Access

Microsoft Entra ID Protection assigns risk scores to sign-ins. Conditional Access can require MFA or block access automatically when risk is elevated.

Conditional Access Configuration Checklist

MFA required for all users via Conditional Access — not just per-user MFA settings

Legacy authentication blocked — no IMAP, POP3, or Basic Auth allowed

Device compliance required for sensitive applications

Admin accounts protected with additional Conditional Access controls

Break-glass emergency access account maintained and excluded from policies

Policies tested in report-only mode before enforcement

Frequently Asked Questions

Configure Conditional Access Correctly

AMVIA configures and manages Microsoft 365 Conditional Access policies — enforcing MFA, blocking legacy authentication, and requiring device compliance across your entire tenant.