Read this first — the order is the whole method
Every change in this dojo can lock somebody out, and the order that feels natural is the order that causes the outage. Turning off the weak method first is the mistake. Nobody should ever be between credentials.
- Audit, then enable, then migrate, then retire. Enable the strong method and move people onto it before you touch the weak one.
- Retire by shrinking scope, not by disabling. Point the method at a group and empty the group. Rollback becomes a membership change instead of an emergency.
- "Microsoft managed" is not "on". It means "whatever Microsoft decides today" — and for Report suspicious activity it currently means off. Set anything you rely on explicitly.
- Enforcement is a Conditional Access policy. So it follows the CA rules: report-only, read the logs, then On. Break-glass excluded from every one.
- Find your service accounts before you start, not when they break. The exclusion you add in a hurry outlives everyone who remembers why.
Full guidance: Plan a phishing-resistant passwordless deployment ↗
Size up your environment
Choose your products and confirm your PKI. Premium reporting and Conditional Access dependencies are shown on each control. If you've been through another dojo, your licence is already filled in.
Do you already operate a PKI for certificate-based authentication?
Walk out with a plan
Your plan reflects recorded answers and progress, including unresolved and deferred controls. Configuration examples require review of permissions, licensing, dependencies and placeholders. PowerShell bundles include an execution stop; read and edit them before deliberately running a selected section.