Terminology Index

Glossary

1 term tagged "conditional-access-configuration"

Open concept maps

Showing 1-1 of 1 term

C
1

Conditional Access Configuration

The detailed setup of conditional access policies in a directory service like Microsoft Entra ID, defining the conditions, signals, and controls that govern sign-ins, with attention to avoiding gaps, lockouts, and misconfigurations attackers exploit.

Configuring conditional access well is exacting directory-security work: policies must cover all sensitive access paths, handle edge cases (break-glass accounts, legacy protocols), and avoid both gaps that let attackers in and overly broad rules that lock out legitimate users. Misconfigured policies are a real attack surface, so this is treated as a hardening discipline within securing the identity directory, alongside privileged-role and app-registration hardening.

Introduced in: Directory Services Security

Examples

  • Ensuring no sensitive sign-in path is left uncovered by a policy.
  • Configuring break-glass accounts so admins are never fully locked out.
  • Closing a gap where legacy authentication bypassed conditional access.

No related terms linked yet.