Introduction
Woodgrove Bank trusts Relecloud with regulated financial data, so Relecloud's leadership needs proof—not just confidence—that every sign-in to that data is controlled, explainable, and defensible under audit. That proof depends on more than any single setting; it depends on the entire authentication and access stack working together, in ways you can verify.
Consider a case that lands on your desk: an engineer signs in to SharePoint from a fully compliant, corporately managed laptop using Microsoft Edge, and nothing blocks the sign-in. Minutes later, on that exact same device, with the same compliance state, the same person tries again in Chrome—and gets blocked. Nothing about the hardware changed, and nothing about the user's identity changed either. Something else decided that outcome, and by the end of this module, you have the tools to find out what.
What you'll learn
- Rank Microsoft Entra authentication methods and scope stronger methods like Passkey (FIDO2) to the groups that need them.
- Configure Microsoft Entra Password Protection with banned password lists and smart lockout.
- Enable self-service password reset for a group and diagnose failed resets by checking registration, lockout, and scope in turn.
- Layer Conditional Access policies that combine with AND logic, and use the Client apps condition to separate modern from legacy sign-ins.
- Investigate a specific sign-in with Sign-in logs, the Conditional Access tab, the Sign-in diagnostic, and the What If tool.
- Configure sign-in risk and user risk policies with Microsoft Entra ID Protection.
By the end of this module, you can configure, layer, and troubleshoot Microsoft Entra authentication methods, password protection, and Conditional Access policies so every sign-in decision at Relecloud is deliberate and provable.