Summary

Completed

You now scope authentication methods to the right groups, block weak and guessable passwords at the tenant boundary, and trace any sign-in decision back to the exact Conditional Access policy that produced it. Instead of taking a control at face value, you can confirm what a policy actually enforces and why.

What you learned

  • You rank Microsoft Entra authentication methods from phishing-resistant to legacy, enable Microsoft Authenticator broadly across the tenant, and scope a stronger method like Passkey (FIDO2) to the specific group that needs it.
  • You configure Microsoft Entra Password Protection with the global and custom banned password lists and smart lockout, and predict which passwords the tenant's scoring algorithm accepts or rejects.
  • You enable self-service password reset for a group, including nested groups, and diagnose failed resets by checking registration counts, lockout thresholds, and group scope in turn.
  • You evaluate how multiple Conditional Access policies combine with AND logic, and how the Client apps condition separates modern authentication clients from legacy clients that can't satisfy MFA.
  • You investigate a specific sign-in using the Sign-in logs, the Conditional Access tab, the Sign-in diagnostic, and the What If tool to confirm which policy applied and why.
  • You resolve why a compliant, managed device passes in one browser and fails in another, and configure separate Conditional Access policies for sign-in risk and user risk with Microsoft Entra ID Protection.

Learn more