Summary

Completed

You can now scope authentication methods, protect passwords, enable self-service password reset, and evaluate Conditional Access decisions using the sign-in record. You can also tell the difference between what a policy is projected to do and what actually happened at runtime.

What you learned

  • You rank Microsoft Entra authentication methods from phishing-resistant to legacy, enable Microsoft Authenticator broadly across the tenant, and scope a stronger method like Passkey (FIDO2) to the specific group that needs it.
  • You configure Microsoft Entra Password Protection with the global and custom banned password lists and smart lockout, and predict which passwords the tenant's scoring algorithm accepts or rejects.
  • You enable self-service password reset for a group and diagnose failed resets by checking enablement scope, method readiness, and temporary verification blocks in turn.
  • You evaluate how multiple Conditional Access policies combine with AND logic, how report-only mode evaluates without enforcing, and how the Client apps condition separates modern authentication clients from legacy clients that can't satisfy MFA.
  • You investigate a specific sign-in with policy results, Authentication Details, Device Info, and the final result. The Sign-in diagnostic provides guidance, while What If estimates policy applicability rather than confirming what happened.
  • You compare Intune device compliance with what a sign-in event actually shows, verify browser prerequisites, and design separate sign-in-risk and user-risk policies. Sign-in risk requires MFA, while user risk uses Require risk remediation.

Learn more