Summary
You now scope authentication methods to the right groups, block weak and guessable passwords at the tenant boundary, and trace any sign-in decision back to the exact Conditional Access policy that produced it. Instead of taking a control at face value, you can confirm what a policy actually enforces and why.
What you learned
- You rank Microsoft Entra authentication methods from phishing-resistant to legacy, enable Microsoft Authenticator broadly across the tenant, and scope a stronger method like Passkey (FIDO2) to the specific group that needs it.
- You configure Microsoft Entra Password Protection with the global and custom banned password lists and smart lockout, and predict which passwords the tenant's scoring algorithm accepts or rejects.
- You enable self-service password reset for a group, including nested groups, and diagnose failed resets by checking registration counts, lockout thresholds, and group scope in turn.
- You evaluate how multiple Conditional Access policies combine with AND logic, and how the Client apps condition separates modern authentication clients from legacy clients that can't satisfy MFA.
- You investigate a specific sign-in using the Sign-in logs, the Conditional Access tab, the Sign-in diagnostic, and the What If tool to confirm which policy applied and why.
- You resolve why a compliant, managed device passes in one browser and fails in another, and configure separate Conditional Access policies for sign-in risk and user risk with Microsoft Entra ID Protection.
Learn more
- Manage Microsoft Entra authentication methods
- Eliminate bad passwords using Microsoft Entra Password Protection
- How self-service password reset works
- Conditional Access conditions, including client apps
- Use the sign-in diagnostic for Microsoft Entra
- Troubleshoot Conditional Access with the What If tool
- Configure sign-in risk and user risk policies