Conditional Access serves as the firewall for identity in a modern organization. Nathan Taylor explains the essential policies every Microsoft tenant needs to block credential stuffing and token stealing. From phishing-resistant MFA to blocking device code flow, this session details the specific rules that secure your environment. You will see how to implement these layers without locking yourself out. It is a baseline for any security conscious IT leader managing Microsoft 365 identities.
Microsoft identity security is no longer just about requiring a password. Nathan Taylor, lead of the Sourcepass Center of Excellence for Microsoft, breaks down the rules for modern access control. You will see how Conditional Access functions as a Zero Trust enforcement layer, evaluating signals before any sensitive data is accessed.
The conversation talks about how to properly scope policies, utilize report only mode, and maintain emergency break glass accounts for recovery. Organizations that implement these layers can block over 99% of common account compromise attempts.
What You’ll Learn:
- How to configure phishing-resistant MFA using FIDO2 passkeys for your most sensitive administrative roles.
- Methods for blocking legacy authentication to stop the vast majority of common credential stuffing attacks.
- The process for requiring managed or compliant devices to neutralize sophisticated token stealing maneuvers.
- Strategies for limiting administrative session lengths to reduce the window of opportunity for threat actors.
- Ways to implement active identity protection using risky sign in and risky user policies with Entra ID P2.
- The importance of separating administrative duties from daily email accounts to harden your organizational posture.
Episode Highlights:
[00:04:15] The Identity Firewall Logic
Nathan describes why modern security relies on Conditional Access as the primary Zero Trust enforcement tool. These rules act as digital gatekeepers, determining exactly how and when a user connects based on specific risk signals.
[00:07:30] Avoiding the Admin Lockout
Implementing strict security can accidentally lock administrators out of their own systems if not handled carefully. This segment outlines the necessity of break glass accounts and the strategic use of report only mode during deployment.
[00:16:30] Redundant Layers for Admins
While MFA for all users is a baseline, administrative accounts require an additional, dedicated layer of protection. This secondary policy ensures that even if an exclusion is made elsewhere, privileged access remains guarded.
[00:20:45] Shutting the Legacy Door
Legacy authentication remains a massive vulnerability because it bypasses modern multi factor checks. Nathan explains how to identify and block these aging protocols while monitoring logs to ensure business continuity isn't disrupted.
[00:25:30] Phishing Resistance with FIDO2
Standard MFA is no longer enough to stop advanced attackers using separate cryptographic channels for authentication. The talk highlights why FIDO2 passkeys are the gold standard for protecting executives and high value data.
[00:31:15] Combating Token Stealing
Threat actors are increasingly replaying stolen tokens to bypass identity checks entirely. Managed device policies solve this by requiring a known, trusted hardware signal before granting any access to the tenant.
About The Host - Nathan Taylor
Nathan Taylor is the Senior Vice President and Global Microsoft Practice Leader at Sourcepass, where he leads the Sourcepass Center of Excellence for Microsoft. His work is grounded in a simple idea: Microsoft should not be complicated. By removing complexity, confusion, and frustration from the Microsoft ecosystem, Nathan helps organizations focus on outcomes while getting the most from their Microsoft investment.
Episode Resources:
Don’t let a single misconfigured rule become your organization's greatest vulnerability. Connect with our team of Microsoft problem solvers to turn these ten Conditional Access policies into secure outcomes for your environment:
Quotes
- "Conditional access is Microsoft's zero trust enforcement layer. I like to call it the firewall rules for identity. It's the rules about where and how and when someone can connect to a tenant. This blocks 97% of the credential stuffing hacks, so it can be blocked by turning a blocking legacy off."
- "If you haven't been playing with FIDO2 passkeys on your tenants, you need to go play with FIDO2 passkeys because they are phishing resistant in ways that none of the other authentication methods are.”
- “FIDO2 passkeys use a separate cryptographic channel to authenticate you. They're not vulnerable to the same token stealing attacks."
- "It's worth looking at PIM PAM. It's very easy to add a couple intra ID P2 licenses to a tenant and build out PIM just in time access capability for those admin roles."