Users and roles
Review all-user baselines, administrators, guests, service accounts, synchronization identities, staged populations, group dependencies, and exclusions with documented purpose and ownership.
The goal is to understand who can reach which resources, under what conditions, with which safeguards—and where exclusions, dependencies, or unsafe changes could weaken that design.
Review all-user baselines, administrators, guests, service accounts, synchronization identities, staged populations, group dependencies, and exclusions with documented purpose and ownership.
Examine cloud-app coverage, user actions, authentication context where used, browser and mobile or desktop clients, device-code flows, and legacy authentication exposure.
Assess multifactor authentication requirements, authentication strengths where applicable, registration dependencies, phishing-resistant options, frequency choices, and user experience.
Trace requirements for compliant or joined devices, supported platforms, unmanaged access, application protection, unknown devices, and the Intune signals behind access decisions.
Review named locations, trusted-network assumptions, country or region logic, network changes, user and sign-in risk policies where licensed, and the response to detected risk.
Inspect sign-in frequency, persistent browser sessions, application-enforced restrictions, continuous access evaluation dependencies, and controls for sensitive workflows.
Place Conditional Access inside the broader Microsoft 365 assessment checklist, review TenantShield data-handling practices, or explore the assessment service.
Run the free checker for an initial signal, or request an assessment for evidence-backed Conditional Access priorities in context.