Entra ID & IdentityHow-To & HardeningRetrospectives

Conditional Access Policy Review Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.

Use this checklist to review your Conditional Access policies.

Coverage

  • A policy requires MFA for all users and all cloud apps (or Security Defaults is on).
  • A policy blocks legacy authentication.
  • A policy requires phishing-resistant MFA for admin roles.
  • A policy protects Azure management (now also enforced by Microsoft's mandatory MFA).
  • Guests and external users are covered.
  • Device code flow is blocked except for approved scenarios.
  • Risk-based policies are configured (if Entra ID P2).
  • Compliant or hybrid-joined devices required for sensitive apps.

Exclusions

  • Break-glass accounts excluded where appropriate — and only those.
  • Every other exclusion is documented with an owner and review date.
  • No large groups excluded "temporarily."
  • Service accounts excluded only where no alternative exists, and protected with workload identity policies or location restrictions.

Microsoft-managed policies

  • All reviewed, with decisions documented.
  • Report-only results checked before enablement dates.

Hygiene

  • Policies follow a naming convention.
  • Report-only policies older than 30 days are either enabled or removed.
  • Disabled policies are reviewed and deleted if unneeded.
  • Changes to Conditional Access are made through change control and alerted on.

Testing

  • The What If tool used to test scenarios before changes.
  • Sign-in logs reviewed for unexpected failures after changes.
conditional access policy review checklistSFI & managed CA policies2023

More on this story