Demystifying Security: Conditional Access
Reviewed and updated in October 2026.
Employees access work resources from desktops, tablets and phones, from the office, from home and from public places. For security and mobility teams, the challenge is to let only authorized users on authorized devices reach corporate resources, while still letting people work productively from anywhere at any time. Conditional Access is the tool built for that balance.
Conditional Access is an access control method that decides at every sign-in whether to allow, block or challenge a request, based on signals such as the user, the device's compliance status, the location, the application and the real-time risk level. It is the policy engine of a Zero Trust architecture: a valid password alone no longer opens the door.
How has access control traditionally worked?
Traditionally, a username and password were enough to access a corporate resource or service from a desktop or mobile device. Only one element, the user, decided whether access was granted.
As organizations move to a Zero Trust architecture, a second element is added: not only the user but also the device must be authorized to access resources and handle corporate data, so that data is not compromised in any of its states, in transit, at rest or in use. Zero Trust also grants only the minimum access required, resource by resource. Conditional Access goes one step further and makes that decision dynamic.
What is Conditional Access?
Conditional Access lets organizations strengthen and fine-tune their access policies with additional signals such as device, location, application and real-time risk. Based on them, a user is allowed to access a service, blocked, or allowed only after additional checks. The term comes from Microsoft, where Conditional Access is part of Microsoft Entra ID; Google offers the same concept for Google Workspace as Context-Aware Access.
How does Conditional Access work?
Conditional Access evaluates several signals to make a decision and enforce organizational policies. Common signals are:
- User: specific users or groups can be targeted with different policies.
- Location: where is the user connecting from? A known, trusted location such as the office; a known, untrusted location such as a predefined region or country; or an unknown location.
- Device: the platform, and whether the device is compliant with company security policy, for example managed by a UEM solution.
- Application: a specific application or group of applications, such as email.
- Real-time risk: a calculated risk for the sign-in or the device, for example a threat detected by a Mobile Threat Defense (MTD) solution.
Unlike a simple allow or block decision, Conditional Access adds a third option that requires further verification before access is granted:
- Block access (most restrictive).
- Allow full or limited access.
- Allow access only after additional requirements are met, such as multi-factor authentication (MFA) or a device marked as compliant. Microsoft documents these options as grant controls.
What does Conditional Access look like in practice?
Sign-in from an unusual location
An employee travels abroad and connects from a public place, such as the airport, on arrival. The user is authenticated and the device is managed and safe, but the location is unusual. An additional confirmation is required, for example approval from another known, trusted device, to make sure the request comes from the user and not from an attacker impersonating them.
Unapproved software
An employee installs an app that seems safe but is not approved. The UEM solution detects it and marks the device as non-compliant. The device status is passed to the identity provider, for example Microsoft Entra ID for Microsoft 365, which blocks access to some or all services, such as email and the intranet, until the issue is fixed and the UEM reports the device as compliant again.
Where is Conditional Access enforced?
Conditional Access is enforced by the identity provider or by the service itself. Applications that sign users in through that identity provider are covered, whether they run on premises or in the cloud. Applications with their own separate sign-in are not, so they need to be connected to the identity provider first.
Conclusion
Moving from a traditional security approach to a more advanced one, Conditional Access is a central tool of any security strategy. It touches all five pillars of CISA's Zero Trust Maturity Model: identity, devices, networks, applications and workloads, and data. It can use signals not only from the service provider itself but also from complementary third-party solutions: the compliance status and enrollment state of a device from a Unified Endpoint Management (UEM) platform, and the device risk level, such as a detected threat, a sideloaded app or disabled encryption, from Mobile Threat Defense (MTD). The more relevant signals involved, the better the decision. How Zero Trust extends to smartphones and tablets is described in How to Extend ZTA to Your Mobility Infrastructure.
Frequently asked questions
What signals does Conditional Access use?
Typically the user or group, the location, the device platform and compliance status, the application being accessed and a real-time risk score for the sign-in or the device.
What is the difference between Conditional Access and MFA?
MFA is one possible requirement. Conditional Access is the policy engine that decides when to require MFA, when to allow access directly and when to block it.
How do UEM and MTD work with Conditional Access?
The UEM reports whether a device is enrolled and compliant, and MTD reports its risk level. The identity provider uses both signals to allow, restrict or block access.
Is Conditional Access only available from Microsoft?
The name comes from Microsoft Entra ID, but the concept is broader. Google Workspace calls it Context-Aware Access, and other identity providers offer comparable policy engines.
ISEC7 advises on UEM platforms such as Microsoft Intune and on Mobile Threat Defense and fits them into your existing environment, the two sources of the device compliance and risk signals Conditional Access relies on. Learn more about endpoint management and endpoint security, or contact us.