Start with Identity
← Glossary
Concept

Conditional Access

Policy-driven access decisions evaluated at sign-in time. Inputs include identity, device, location, risk signals, and application sensitivity. Microsoft Entra Conditional Access popularized the term; equivalent capability exists across IAM platforms.

Conditional access is where most organizations actually implement zero trust, because it is the one place policy can consider identity, device, location, and risk together at the moment of access. Two failure modes recur: exclusions that were added for a migration and never removed, and policies that require "MFA" generically rather than a phishing-resistant method, which relay kits satisfy. Audit the exclusion list more often than the policy list.

See also: what is zero trust, adaptive auth, device posture, phishing-resistant MFA

Last reviewed By SWI Community TeamSuggest a correctionHow we research