Skip to content
All insights
ProtectMicrosoft SecurityHow-To GuideJune 7, 2026

Conditional Access starter policies for a small business

The Short Version
  • Create and exclude a break-glass account before any other policy.
  • Build three core policies: require MFA, block legacy auth, and require a compliant device.
  • Start every policy in report-only and review the results first.
  • Turn policies on one at a time so you know what broke what.
Bottom line: A safe Conditional Access baseline tightens access without locking your own admins out.

Loading article…

See where you stand. Then move forward.

Book a free intro call. We'll talk through where you are today and map a plan for growth, protection, automation, and alignment.

30 minutesNo obligationGet an initial estimate within one week