Summary
You can now scope authentication methods, protect passwords, enable self-service password reset, and evaluate Conditional Access decisions using the sign-in record. You can also tell the difference between what a policy is projected to do and what actually happened at runtime.
What you learned
- You rank Microsoft Entra authentication methods from phishing-resistant to legacy, enable Microsoft Authenticator broadly across the tenant, and scope a stronger method like Passkey (FIDO2) to the specific group that needs it.
- You configure Microsoft Entra Password Protection with the global and custom banned password lists and smart lockout, and predict which passwords the tenant's scoring algorithm accepts or rejects.
- You enable self-service password reset for a group and diagnose failed resets by checking enablement scope, method readiness, and temporary verification blocks in turn.
- You evaluate how multiple Conditional Access policies combine with AND logic, how report-only mode evaluates without enforcing, and how the Client apps condition separates modern authentication clients from legacy clients that can't satisfy MFA.
- You investigate a specific sign-in with policy results, Authentication Details, Device Info, and the final result. The Sign-in diagnostic provides guidance, while What If estimates policy applicability rather than confirming what happened.
- You compare Intune device compliance with what a sign-in event actually shows, verify browser prerequisites, and design separate sign-in-risk and user-risk policies. Sign-in risk requires MFA, while user risk uses Require risk remediation.
Learn more
- Manage Microsoft Entra authentication methods
- Eliminate bad passwords using Microsoft Entra Password Protection
- How self-service password reset works
- Conditional Access conditions, including client apps
- Use the sign-in diagnostic for Microsoft Entra
- Troubleshoot Conditional Access with the What If tool
- Configure sign-in risk and user risk policies