Conditional Access is the bouncer for your Microsoft 365 tenant, but the policy screen assumes you already know kung fu. This dojo doesn't. Answer eight questions about your setup, then work through the belts. Every policy comes with the attack it stops, the MITRE ATT&CK techniques behind it, and the exact clicks to build it. Mark your progress and walk out with a deployment plan.
Built on the shoulders of Joey Verlinden's Conditional Access Baseline ↗ — many thanks, Joey, for the incredible contribution to the community.
Step 0 — Break-glass accounts (before you touch anything)
A misconfigured policy can lock every admin out — including you. Break-glass accounts are the mat you land on. The Conditional Access rule for them is one line, and it has no exceptions:
- Exclude them from every Conditional Access policy you ever make. Every one. Including the ones you're about to build below, and the one you'll add in a hurry next year.
Everything else about these accounts — creating them, credentials, monitoring, and protecting them with a restricted management administrative unit so a compromised Global Admin can't delete them — is owned by the Privileged Access Dojo, so the guidance lives in exactly one place. Microsoft's reference: Manage emergency access accounts ↗
Size up your environment
Eight quick questions. The dojo tailors the policy set to what you actually run — and tells you honestly when a policy isn't for you.
Which licences do you have in the tenant? Select all that apply.
Do you manage devices with Intune?
Do external guests collaborate in your tenant?
What phones/tablets reach work email or Teams?
Does anyone manage Azure resources?
How far do you want to push passkeys / FIDO2?
Do you want to go passwordless?
What do staff work on?
Step 0.5 — Passwordless readiness
Passwordless isn't a Conditional Access setting. It's a registration project with a Conditional Access policy at the end of it. Enforce the policy before people hold the credential and you lock them out. Here's what has to be true first.
Walk out with a plan
Your deployment plan lists every in-scope policy with its status, MITRE references and Microsoft Learn source. The JSON bundle contains Graph API definitions for your in-scope policies — every one set to report-only, because that's how professionals roll things out. Swap in your break-glass group ID before importing (Entra admin center → Conditional Access → Policies → Upload policy file).