Conditional Access
Policy-driven access decisions evaluated at sign-in time. Inputs include identity, device, location, risk signals, and application sensitivity. Microsoft Entra Conditional Access popularized the term; equivalent capability exists across IAM platforms.
Conditional access is where most organizations actually implement zero trust, because it is the one place policy can consider identity, device, location, and risk together at the moment of access. Two failure modes recur: exclusions that were added for a migration and never removed, and policies that require "MFA" generically rather than a phishing-resistant method, which relay kits satisfy. Audit the exclusion list more often than the policy list.
See also: what is zero trust, adaptive auth, device posture, phishing-resistant MFA
Related on Start with Identity
- GlossaryStep-up Authentication
Requiring additional authentication when a user attempts a higher-risk action, such as changing email or initiating a large payment. Implemented via OIDC `acr_v
- GlossaryZTNA
Zero Trust Network Access. The product category that replaces VPNs with identity-aware proxies. ZTNA grants access to specific applications based on identity an
- GlossaryAccess Certification
Periodic review of who has access to what, with managers or resource owners attesting that access is still appropriate. A regulatory requirement in many industr
- GuideConditional Access Policies: A Complete Implementation Guide for Microsoft Entra
Master Microsoft Entra conditional access with risk-based policies, device compliance rules, location-based restrictions, and real-world deployment patterns.
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a
- Blog94 percent of enterprises say they can revoke access in 24 hours. 35 percent found out they couldn't.
FIDO Alliance and HID surveyed 500 IT and security decision-makers for The State of Physical and Digital Identity in the Enterprise. The headline gap: near-univ