Method
How to approach a Conditional Access design, review or rollout.
A Conditional Access baseline policy set
A sequenced set of policies to deploy, in the order that keeps prerequisites ahead of impact.
Conditional Access lockout risk model
How to rate the risk that a policy locks out its own administrators, and what reduces it.
How to review a Conditional Access policy
A repeatable review order, severity definitions, and the findings that recur most.
Gathering environment detail for a design
The few questions that actually change a Conditional Access design, and sensible defaults for the rest.
Report-only rollout and rollback
Pre-flight checks, pilot design, enforcement criteria, and how to get back out safely.
Reviewing emergency access (break-glass) accounts
A full checklist for the accounts that exist for the day everything else fails.
Reference
Lookup material: schema, error codes, identifiers, licensing.
Sign-in error codes and diagnosis
Which codes mean Conditional Access, which only look like it, and how to tell them apart.
Microsoft Graph conditionalAccessPolicy schema
Every condition, grant and session control, and the review heuristics keyed to each.
Licensing and capability tiers
Which controls need P1, which need P2, and why entitlement is not the same as assignment.
Well-known application and role identifiers
The GUIDs and enumeration values you need when reading or writing policy JSON.
A naming convention for policies
Names that convey purpose, scope and control without opening the policy.
Microsoft guidance
Distilled from Microsoft's own documentation, with the caveats that matter.
Microsoft's design principles
Deny-by-exception, the 240-policy limit, and why a group-scoped policy restricts nobody.
Microsoft-managed policies
Policies Microsoft creates in your tenant, and the 45-day clock before they enable themselves.
The phased rollout
Microsoft's three-phase deployment, its gate conditions, and the testing step most people skip.
Resilience and contingency policies
Backup policies held in reserve for an outage, and how to degrade without going open.
Emergency access guidance
The five scenarios break-glass accounts exist for, including one pure PIM trap.
Guests and external identities
Three grant controls that simply do not work for guests, and what to use instead.
Zero Trust identity recommendations
The attack narrative behind each control — what an attacker does when it is missing.
Token protection: scope and limits
Supported apps and devices, the unsupported deployment types, and the device filters that exclude them.
Troubleshooting with the sign-in logs
Service dependencies and audience reporting — two causes invisible from the error code.