Microsoft 365 & Cloud
Conditional Access explained for small businesses
What Microsoft Entra Conditional Access does, which Microsoft 365 plan includes it, the first six policies a UK small business should enable, and lockout.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
Conditional Access is the Microsoft Entra feature that decides whether a Microsoft 365 sign-in is allowed, blocked or challenged, based on who the user is, their device, their location and what they are opening. It is included with Microsoft 365 Business Premium and lets a small business enforce MFA, block untrusted countries and require managed devices without extra tools.
Most Microsoft 365 breaches in small businesses start the same way: a phished or reused password, a sign-in from a country the business has never traded with, and a mailbox rule that quietly forwards invoices to an attacker. Conditional Access is the control that stops that sign-in at the door. It is built into Microsoft 365 Business Premium, it needs no extra software, and most tenants Dig IT reviews have it either switched off or half-configured.
What Conditional Access actually is
Conditional Access is a policy engine inside Microsoft Entra ID, the identity service behind every Microsoft 365 login. Each time someone signs in, Entra collects a set of signals and checks them against your policies before deciding what to do.
The signals include:
- Who is signing in: a specific user, group or role such as global administrator.
- What they are trying to reach: Exchange, SharePoint, Teams, the admin portals or every cloud app.
- Where they are: a named location such as your office IP range, the UK, or anywhere else.
- Which device they are using: whether it is enrolled in Intune and marked compliant, and which operating system.
- How they are connecting: a modern app such as Outlook, a browser, or a legacy protocol such as basic-auth IMAP.
The policy then applies a control: allow, block, or allow only if a condition is met, such as completing MFA or using a compliant device. Microsoft documents the full model on Microsoft Learn.
Think of it as a doorman with a list of rules rather than a single lock. The lock (the password) still matters, but the doorman asks further questions before letting anyone through.
Which plans include it
Conditional Access needs a Microsoft Entra ID P1 licence. In practice, for UK small businesses, that means:
| Plan | Conditional Access | Alternative |
|---|---|---|
| Business Basic | No | Security Defaults |
| Business Standard | No | Security Defaults |
| Business Premium | Yes (Entra ID P1 included) | Not needed |
| Microsoft 365 E3 / E5 | Yes | Not needed |
| Entra ID P1 standalone add-on | Yes | Can be added to Basic or Standard |
Security Defaults, the free alternative, is a single switch that requires MFA registration for everyone, blocks legacy authentication and protects privileged actions. It is far better than nothing, and every tenant on Basic or Standard should have it on. What it cannot do is vary the rules: it cannot require a managed device for email, block foreign sign-ins or exempt a conference room account. That flexibility is what you are paying for in Premium, alongside Intune and Defender for Business, as set out in the Business plan comparison.
The first six policies for a small business
These are the policies Dig IT deploys as a baseline through its Microsoft 365 security service. Each should be created in report-only mode first, reviewed for a few days, then enforced.
- Require MFA for all users on all cloud apps. The foundation. Exclude only the break-glass account and any genuine service accounts that have their own protection.
- Block legacy authentication. Older protocols such as basic-auth IMAP, POP and SMTP cannot perform MFA, so attackers target them deliberately. Block them everywhere and fix the one old scanner or application that breaks.
- Require MFA and a stronger method for administrators. Global administrators and other privileged roles should use phishing-resistant methods such as a FIDO2 key or Windows Hello for Business, and should sign in from a managed device.
- Block sign-ins from outside your trading countries. Define the UK, and any country where staff genuinely work, as named locations. Block everything else. This removes most automated password-spray traffic in one policy.
- Require a compliant device for Office apps and email. Once Intune is managing your laptops and phones, require that a device is marked compliant before it can open Outlook, Teams or SharePoint. A stolen password on an unmanaged laptop then gets nowhere.
- Block or limit access from unmanaged devices in the browser. For staff who occasionally use a home PC, allow browser-only access with download disabled rather than full sync.
The NCSC's guidance on multi-factor authentication for online services backs the same priorities: MFA for everyone, stronger protection for privileged accounts, and a preference for phishing-resistant methods where the risk justifies it.
The mistakes that cause lockouts
Conditional Access has a reputation for locking businesses out of their own tenant. Almost every case comes down to one of four errors.
- No break-glass account. Every tenant needs at least one emergency global administrator excluded from all policies, with a long random password stored offline and its use monitored. Without it, a policy that blocks all sign-ins blocks the person who needs to fix it.
- Skipping report-only mode. Enforcing a policy on day one, with no data on who it affects, is how a receptionist's shared tablet ends up blocked on a Monday morning.
- Forgetting service accounts and devices. Meeting room systems, multifunction printers that scan to email, and line-of-business applications often sign in as users. Identify them in discovery and handle them with a specific exclusion or an app password, not a blanket exemption.
- Enabling Security Defaults and Conditional Access together. They are mutually exclusive. Turn Security Defaults off only once your Conditional Access baseline is in report-only mode and reviewed.
What Conditional Access does not do
It is an access control, not a complete security programme. It will not stop a user who has passed MFA from clicking a malicious link, it cannot see what happens on a device after sign-in, and it does nothing for data that has already been synced to a laptop. Those gaps are covered by Defender for Business for endpoints, by Defender for Office 365 for links and attachments, and by a proper Microsoft 365 backup for the data itself. Risk-based policies, which react to leaked credentials or impossible-travel sign-ins automatically, need the more expensive Entra ID P2 licence and are usually a later step for businesses under 100 people.
Conditional Access also depends on good hygiene elsewhere. The broader Microsoft 365 security settings checklist covers audit logging, mailbox forwarding rules, external sharing and the other settings that sit alongside it.
A worked example
A 25-person accountancy practice in Hertford moves to Business Premium. Before Conditional Access, staff had MFA "when prompted", two partners had never registered it, and sign-in logs showed daily failed attempts from three continents. After a two-week rollout: MFA is enforced for everyone, legacy protocols are blocked, sign-ins are restricted to the UK with an exclusion group for one partner who works abroad in the summer, and client files in SharePoint open only from Intune-managed laptops. The daily foreign sign-in attempts still appear in the logs, and every one of them is now blocked before a password is even tested. That is the whole point.
What to do next
If your business is on Business Premium and you are not sure whether Conditional Access is enforced, or you are on Basic or Standard and relying on Security Defaults without knowing it, a short review of the sign-in logs and policy set will tell you where you stand. Dig IT includes this in its IT health check for businesses across Hertfordshire, west Essex and London.

