Enterprise Identity & Access Management Platform  ·  View 13 of 27  ·  Runtime

Conditional Access Policy Matrix

Eight personas, and what each is required to prove before access is granted.

Editable source SVG draw.io All views
Signals evaluated
Signals evaluated
Authentication strength
Authentication strength
Device & network
Device & network
Session control
Session control
Outcome
Outcome
Employee, managed device
Employee, managed device
Low user & sign-in risk
Low user & sign-in risk
Passkey or MFA
Passkey or MFA
Compliant device
Compliant device
Sign-in frequency 12 h
Sign-in frequency 12 h
Grant
Grant
Administrator to portals
Administrator to portals
Any privileged role
Any privileged role
Phishing-resistant only
Phishing-resistant only
Privileged workstation
Privileged workstation
No persistent session
No persistent session
Grant
Grant
PIM role activation
PIM role activation
Activation request
Activation request
Phishing-resistant + approval
Phishing-resistant + approval
Compliant PAW
Compliant PAW
Lifetime = activation
Lifetime = activation
Grant, time-bound
Grant, time-bound
High-risk sign-in
High-risk sign-in
ID Protection: high
ID Protection: high
Password change + MFA
Password change + MFA
Any
Any
Revoke all sessions
Revoke all sessions
Block until remediated
Block until remediated
B2B guest
B2B guest
Guest + resource app
Guest + resource app
MFA trusted from home tenant
MFA trusted from home tenant
Unmanaged permitted
Unmanaged permitted
1 h, no download
1 h, no download
Grant, restricted
Grant, restricted
Workload identity
Workload identity
Service principal sign-in
Service principal sign-in
Not interactive
Not interactive
Named location allowlist
Named location allowlist
Not applicable
Not applicable
Block outside allowlist
Block outside allowlist
Legacy authentication
Legacy authentication
POP · IMAP · SMTP basic
POP · IMAP · SMTP basic
Cannot satisfy MFA
Cannot satisfy MFA
Any
Any
Not applicable
Not applicable
Block, all users
Block, all users
Break-glass accounts
Break-glass accounts
Excluded from all but one
Excluded from all but one
FIDO2 hardware key only
FIDO2 hardware key only
Any — lockout safety
Any — lockout safety
Alert on every sign-in
Alert on every sign-in
Grant + P1 alert
Grant + P1 alert
Conditional Access Policy Matrix
Conditional Access Policy Matrix
Read as rows, not policies: a persona is the unit a reviewer can reason about. The eight rows compile to 38 Conditional Access policies deployed as code, each in report-only for 14 days before enforcement.
Read as rows, not policies: a persona is the unit a reviewer can reason about. The eight rows compile to 38 Conditional Access policies deployed as code, each in report-only for 14 days before enforcement.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

Why a matrix

  • Personas are the unit a reviewer can reason about; individual policies are not. These eight rows compile to 38 deployed policies, and the rows are what gets signed off.
  • Every row has an explicit outcome, including the two that are Block. A Conditional Access estate with no block rules is a set of suggestions.
  • Break-glass is a row rather than a footnote, because its exclusions are the most security-relevant configuration in the tenant and they must be visible to be reviewed.

Rollout discipline

  • Every policy ships in report-only mode for 14 days, and the impact query must show zero unexpected blocks before enforcement.
  • Policies are deployed from JSON in the IaC repository (view 21), so a change is a pull request with a diff rather than a portal edit nobody can reconstruct.
  • Workload identities are targeted by Conditional Access too, restricted to named locations. That is the control that turns a leaked service principal secret from access into a blocked sign-in.

Assumptions and residuals

  • Legacy authentication is fully blocked. Confirm no business-critical application still needs it — this is the change most likely to cause an outage on day one.
  • Guests are trusted for MFA satisfied in their home tenant. That transfers part of the assurance to 34 partner organisations, which is a deliberate and reviewable trade.
  • Privileged Access Workstations are assumed available for all 190 administrators. If they are not, the administrator row weakens to compliant-device-only.