Skip to main content
Dig IT Solutions logo

Microsoft 365 & Cloud

Conditional Access explained for small businesses

What Microsoft Entra Conditional Access does, which Microsoft 365 plan includes it, the first six policies a UK small business should enable, and lockout.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

Conditional Access is the Microsoft Entra feature that decides whether a Microsoft 365 sign-in is allowed, blocked or challenged, based on who the user is, their device, their location and what they are opening. It is included with Microsoft 365 Business Premium and lets a small business enforce MFA, block untrusted countries and require managed devices without extra tools.

Most Microsoft 365 breaches in small businesses start the same way: a phished or reused password, a sign-in from a country the business has never traded with, and a mailbox rule that quietly forwards invoices to an attacker. Conditional Access is the control that stops that sign-in at the door. It is built into Microsoft 365 Business Premium, it needs no extra software, and most tenants Dig IT reviews have it either switched off or half-configured.

What Conditional Access actually is

Conditional Access is a policy engine inside Microsoft Entra ID, the identity service behind every Microsoft 365 login. Each time someone signs in, Entra collects a set of signals and checks them against your policies before deciding what to do.

The signals include:

  • Who is signing in: a specific user, group or role such as global administrator.
  • What they are trying to reach: Exchange, SharePoint, Teams, the admin portals or every cloud app.
  • Where they are: a named location such as your office IP range, the UK, or anywhere else.
  • Which device they are using: whether it is enrolled in Intune and marked compliant, and which operating system.
  • How they are connecting: a modern app such as Outlook, a browser, or a legacy protocol such as basic-auth IMAP.

The policy then applies a control: allow, block, or allow only if a condition is met, such as completing MFA or using a compliant device. Microsoft documents the full model on Microsoft Learn.

Think of it as a doorman with a list of rules rather than a single lock. The lock (the password) still matters, but the doorman asks further questions before letting anyone through.

Which plans include it

Conditional Access needs a Microsoft Entra ID P1 licence. In practice, for UK small businesses, that means:

PlanConditional AccessAlternative
Business BasicNoSecurity Defaults
Business StandardNoSecurity Defaults
Business PremiumYes (Entra ID P1 included)Not needed
Microsoft 365 E3 / E5YesNot needed
Entra ID P1 standalone add-onYesCan be added to Basic or Standard

Security Defaults, the free alternative, is a single switch that requires MFA registration for everyone, blocks legacy authentication and protects privileged actions. It is far better than nothing, and every tenant on Basic or Standard should have it on. What it cannot do is vary the rules: it cannot require a managed device for email, block foreign sign-ins or exempt a conference room account. That flexibility is what you are paying for in Premium, alongside Intune and Defender for Business, as set out in the Business plan comparison.

The first six policies for a small business

These are the policies Dig IT deploys as a baseline through its Microsoft 365 security service. Each should be created in report-only mode first, reviewed for a few days, then enforced.

  1. Require MFA for all users on all cloud apps. The foundation. Exclude only the break-glass account and any genuine service accounts that have their own protection.
  2. Block legacy authentication. Older protocols such as basic-auth IMAP, POP and SMTP cannot perform MFA, so attackers target them deliberately. Block them everywhere and fix the one old scanner or application that breaks.
  3. Require MFA and a stronger method for administrators. Global administrators and other privileged roles should use phishing-resistant methods such as a FIDO2 key or Windows Hello for Business, and should sign in from a managed device.
  4. Block sign-ins from outside your trading countries. Define the UK, and any country where staff genuinely work, as named locations. Block everything else. This removes most automated password-spray traffic in one policy.
  5. Require a compliant device for Office apps and email. Once Intune is managing your laptops and phones, require that a device is marked compliant before it can open Outlook, Teams or SharePoint. A stolen password on an unmanaged laptop then gets nowhere.
  6. Block or limit access from unmanaged devices in the browser. For staff who occasionally use a home PC, allow browser-only access with download disabled rather than full sync.

The NCSC's guidance on multi-factor authentication for online services backs the same priorities: MFA for everyone, stronger protection for privileged accounts, and a preference for phishing-resistant methods where the risk justifies it.

The mistakes that cause lockouts

Conditional Access has a reputation for locking businesses out of their own tenant. Almost every case comes down to one of four errors.

  • No break-glass account. Every tenant needs at least one emergency global administrator excluded from all policies, with a long random password stored offline and its use monitored. Without it, a policy that blocks all sign-ins blocks the person who needs to fix it.
  • Skipping report-only mode. Enforcing a policy on day one, with no data on who it affects, is how a receptionist's shared tablet ends up blocked on a Monday morning.
  • Forgetting service accounts and devices. Meeting room systems, multifunction printers that scan to email, and line-of-business applications often sign in as users. Identify them in discovery and handle them with a specific exclusion or an app password, not a blanket exemption.
  • Enabling Security Defaults and Conditional Access together. They are mutually exclusive. Turn Security Defaults off only once your Conditional Access baseline is in report-only mode and reviewed.

What Conditional Access does not do

It is an access control, not a complete security programme. It will not stop a user who has passed MFA from clicking a malicious link, it cannot see what happens on a device after sign-in, and it does nothing for data that has already been synced to a laptop. Those gaps are covered by Defender for Business for endpoints, by Defender for Office 365 for links and attachments, and by a proper Microsoft 365 backup for the data itself. Risk-based policies, which react to leaked credentials or impossible-travel sign-ins automatically, need the more expensive Entra ID P2 licence and are usually a later step for businesses under 100 people.

Conditional Access also depends on good hygiene elsewhere. The broader Microsoft 365 security settings checklist covers audit logging, mailbox forwarding rules, external sharing and the other settings that sit alongside it.

A worked example

A 25-person accountancy practice in Hertford moves to Business Premium. Before Conditional Access, staff had MFA "when prompted", two partners had never registered it, and sign-in logs showed daily failed attempts from three continents. After a two-week rollout: MFA is enforced for everyone, legacy protocols are blocked, sign-ins are restricted to the UK with an exclusion group for one partner who works abroad in the summer, and client files in SharePoint open only from Intune-managed laptops. The daily foreign sign-in attempts still appear in the logs, and every one of them is now blocked before a password is even tested. That is the whole point.

What to do next

If your business is on Business Premium and you are not sure whether Conditional Access is enforced, or you are on Basic or Standard and relying on Security Defaults without knowing it, a short review of the sign-in logs and policy set will tell you where you stand. Dig IT includes this in its IT health check for businesses across Hertfordshire, west Essex and London.

Frequently asked questions

Which Microsoft 365 plans include Conditional Access?
Conditional Access requires a Microsoft Entra ID P1 licence, which is included in Microsoft 365 Business Premium, Microsoft 365 E3 and E5, and can also be bought as a standalone add-on. Business Basic and Business Standard do not include it. Those plans can use Security Defaults instead, which enforces MFA for everyone and blocks legacy authentication but offers no way to tailor the rules.
What is the difference between Security Defaults and Conditional Access?
Security Defaults is a single on-or-off switch that requires MFA for all users, blocks legacy authentication and protects admin actions. It is free and a sensible minimum. Conditional Access replaces it with individual policies you write, so you can require MFA only outside the office, block sign-ins from countries you do not operate in, or insist on a managed device for email. The two cannot be enabled at the same time.
Will Conditional Access lock my staff out?
Only if a policy is written badly, which is why every policy should be created in report-only mode first. Report-only logs what the policy would have done without enforcing it, so you can see who would be blocked before switching it on. Every tenant should also have a break-glass administrator account excluded from all policies, stored securely, for use if a policy misfires.
Does Conditional Access replace MFA?
No. Conditional Access is the engine that decides when MFA is required, and it depends on MFA being registered for each user. The usual pattern is a policy that requires MFA for all users on all cloud apps, then further policies that add conditions such as device compliance or location. Without MFA registered, a Conditional Access policy requiring it will simply prompt the user to set it up.
Is Conditional Access needed for Cyber Essentials?
Cyber Essentials requires multi-factor authentication for all users of cloud services and expects administrative accounts to be protected. Security Defaults can meet the MFA requirement, but Conditional Access makes the evidence clearer and lets you enforce stronger controls for administrators. Many assessors and cyber insurers ask specifically about Conditional Access policies, so having them documented helps.
Can Conditional Access block sign-ins from outside the UK?
Yes. You define named locations in Entra, such as the United Kingdom or your office's public IP address, and write a policy that blocks all sign-ins from anywhere else. Staff who travel can be handled with a group exclusion or a temporary change. This single policy removes a large share of automated password-spray attempts, which mostly originate from outside the country.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us