Conditional Access Policy Review Checklist
Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.
Use this checklist to review your Conditional Access policies.
Coverage
- A policy requires MFA for all users and all cloud apps (or Security Defaults is on).
- A policy blocks legacy authentication.
- A policy requires phishing-resistant MFA for admin roles.
- A policy protects Azure management (now also enforced by Microsoft's mandatory MFA).
- Guests and external users are covered.
- Device code flow is blocked except for approved scenarios.
- Risk-based policies are configured (if Entra ID P2).
- Compliant or hybrid-joined devices required for sensitive apps.
Exclusions
- Break-glass accounts excluded where appropriate — and only those.
- Every other exclusion is documented with an owner and review date.
- No large groups excluded "temporarily."
- Service accounts excluded only where no alternative exists, and protected with workload identity policies or location restrictions.
Microsoft-managed policies
- All reviewed, with decisions documented.
- Report-only results checked before enablement dates.
Hygiene
- Policies follow a naming convention.
- Report-only policies older than 30 days are either enabled or removed.
- Disabled policies are reviewed and deleted if unneeded.
- Changes to Conditional Access are made through change control and alerted on.
Testing
- The What If tool used to test scenarios before changes.
- Sign-in logs reviewed for unexpected failures after changes.