Glossary · simply explained

Conditional access

Conditional access makes access decisions context-dependent: instead of a blanket login, every access request evaluates signals such as identity, device posture, location, application and risk assessment — and the policy decides: allow, require additional verification or block.

This is Zero Trust in practice: trust is no longer a property of the network but the result of a check — renewed at every login.

How do conditional access policies work?

A policy combines conditions and controls: if a user of the finance group (condition) accesses the ERP (condition) from an unmanaged device (condition), then require phishing-resistant MFA and block downloads (controls). Signals come from the IdP, device management and risk engines — such as impossible travel or known-compromised credentials.

Effective rulebooks stay small and clear: a few well-founded policies with defined exceptions beat a sprawl of special cases nobody can oversee. Starting in report-only mode shows the impact before rules go live.

Typical policies in practice

  • MFA or passkey mandatory for everyone — phishing-resistant for administrators.
  • Access to sensitive applications only from managed, compliant devices.
  • Blocking legacy authentication without modern verification options.
  • Risky sign-ins: additional verification or block on anomalies.

Frequently asked questions about Conditional access

What does conditional access actually check?

Depending on the platform: identity and groups, device posture and compliance, location and network, target application, session and sign-in risk. From these signals the policy decides per access — allow, tighten or block.

Is conditional access the same as MFA?

No — MFA is one of the possible controls conditional access requests situationally. The value lies in the gradation: routine access stays smooth, risky constellations get additional checks or are stopped.

How do I start without operational disruption?

In report-only mode: let policies only log at first, analyse the impact, define exceptions — then arm group by group, starting with administrators. An emergency account outside the rules prevents locking yourself out.

Does conditional access work for internal applications too?

Yes — via ZTNA: platforms such as Cloudflare Access put the same context-based check in front of internal applications, including device posture. One consistent rulebook applies to SaaS and self-hosted alike — a core promise of Zero Trust.

What does device compliance as a condition mean?

Device management (MDM/UEM) reports whether a device meets requirements — encrypted, patched, protection active. Policies tie access to that: sensitive data only on devices whose state the company knows and controls.

Open questions about this in your environment? KAEMI advises you in line with your requirements and can also take over ongoing management.