Conditional Access
Bedingter Zugriff
Conditional Access is Microsoft Entra's Zero Trust policy engine. At its core it is if-then rules: "if a user wants to access Microsoft 365, then they must pass MFA / the device must be compliant". Signals include user, location, device, app, and risk. Together with Intune compliance, only trusted devices are allowed.
Path in the Intune admin center
📍 Entra ID › Bedingter ZugriffHands-on tasks
- Create a Compliance Policy with security baselinesMicrosoft Intune - Hands-on Course · Module 12
- Custom compliance - check what the template cannotMicrosoft Intune - Hands-on Course · Module 12
- Create and understand your first CA policyMicrosoft Intune - Hands-on Course · Conditional Access
- Block legacy authentication - the most important baseline policyMicrosoft Intune - Hands-on Course · Conditional Access
- Deploy a root certificate and understand certificate typesMicrosoft Intune - Hands-on Course · Deploy certificates (trusted root, SCEP, PKCS)
- Issue a SCEP certificate and use it for Wi-Fi (EAP-TLS)Microsoft Intune - Hands-on Course · Deploy certificates (trusted root, SCEP, PKCS)
- Turning app protection into an access condition (Conditional Access)Microsoft Intune - Hands-on Course · Module 20
Jump straight to the matching course task (sign-in required).
On Microsoft Learn
Related terms