Reviewed and updated in October 2026.
Employees access work resources from desktops, tablets and phones, from the office, from home and from public places. For security and mobility teams, the challenge is to let only authorized users on authorized devices reach corporate resources, while still letting people work productively from anywhere at any time. Conditional Access is the tool built for that balance.
Conditional Access is an access control method that decides at every sign-in whether to allow, block or challenge a request, based on signals such as the user, the device's compliance status, the location, the application and the real-time risk level. It is the policy engine of a Zero Trust architecture: a valid password alone no longer opens the door.
Traditionally, a username and password were enough to access a corporate resource or service from a desktop or mobile device. Only one element, the user, decided whether access was granted.
As organizations move to a Zero Trust architecture, a second element is added: not only the user but also the device must be authorized to access resources and handle corporate data, so that data is not compromised in any of its states, in transit, at rest or in use. Zero Trust also grants only the minimum access required, resource by resource. Conditional Access goes one step further and makes that decision dynamic.
Conditional Access lets organizations strengthen and fine-tune their access policies with additional signals such as device, location, application and real-time risk. Based on them, a user is allowed to access a service, blocked, or allowed only after additional checks. The term comes from Microsoft, where Conditional Access is part of Microsoft Entra ID; Google offers the same concept for Google Workspace as Context-Aware Access.
Conditional Access evaluates several signals to make a decision and enforce organizational policies. Common signals are:
Unlike a simple allow or block decision, Conditional Access adds a third option that requires further verification before access is granted:
An employee travels abroad and connects from a public place, such as the airport, on arrival. The user is authenticated and the device is managed and safe, but the location is unusual. An additional confirmation is required, for example approval from another known, trusted device, to make sure the request comes from the user and not from an attacker impersonating them.
An employee installs an app that seems safe but is not approved. The UEM solution detects it and marks the device as non-compliant. The device status is passed to the identity provider, for example Microsoft Entra ID for Microsoft 365, which blocks access to some or all services, such as email and the intranet, until the issue is fixed and the UEM reports the device as compliant again.
Conditional Access is enforced by the identity provider or by the service itself. Applications that sign users in through that identity provider are covered, whether they run on premises or in the cloud. Applications with their own separate sign-in are not, so they need to be connected to the identity provider first.
Moving from a traditional security approach to a more advanced one, Conditional Access is a central tool of any security strategy. It touches all five pillars of CISA's Zero Trust Maturity Model: identity, devices, networks, applications and workloads, and data. It can use signals not only from the service provider itself but also from complementary third-party solutions: the compliance status and enrollment state of a device from a Unified Endpoint Management (UEM) platform, and the device risk level, such as a detected threat, a sideloaded app or disabled encryption, from Mobile Threat Defense (MTD). The more relevant signals involved, the better the decision. How Zero Trust extends to smartphones and tablets is described in How to Extend ZTA to Your Mobility Infrastructure.
Typically the user or group, the location, the device platform and compliance status, the application being accessed and a real-time risk score for the sign-in or the device.
MFA is one possible requirement. Conditional Access is the policy engine that decides when to require MFA, when to allow access directly and when to block it.
The UEM reports whether a device is enrolled and compliant, and MTD reports its risk level. The identity provider uses both signals to allow, restrict or block access.
The name comes from Microsoft Entra ID, but the concept is broader. Google Workspace calls it Context-Aware Access, and other identity providers offer comparable policy engines.
ISEC7 advises on UEM platforms such as Microsoft Intune and on Mobile Threat Defense and fits them into your existing environment, the two sources of the device compliance and risk signals Conditional Access relies on. Learn more about endpoint management and endpoint security, or contact us.