The Short Version
- Create and exclude a break-glass account before any other policy.
- Build three core policies: require MFA, block legacy auth, and require a compliant device.
- Start every policy in report-only and review the results first.
- Turn policies on one at a time so you know what broke what.
Bottom line: A safe Conditional Access baseline tightens access without locking your own admins out.
Loading article…