Security Ninja

Authentication Dojo

Conditional Access decides when to challenge someone. This decides what counts as a challenge, and how people get enrolled in the first place. Requiring MFA means very little if the method behind it is a text message — and "Require MFA" accepts exactly that. Every setting here lives in Entra ID → Authentication methods, and almost none of it needs a licence you don't already have.

Recorded progress
0 / 1000
Current Rank
No belt yet
0 completed 0 in progress 0 in scope

User-recorded progress; not tenant-verified.

Read this first — the order is the whole method

Every change in this dojo can lock somebody out, and the order that feels natural is the order that causes the outage. Turning off the weak method first is the mistake. Nobody should ever be between credentials.

Full guidance: Plan a phishing-resistant passwordless deployment ↗

Size up your environment

Choose your products and confirm your PKI. Premium reporting and Conditional Access dependencies are shown on each control. If you've been through another dojo, your licence is already filled in.

Which licences do you hold? Select all that apply.
More products and add-ons

Check assignments for each affected user, cloud and feature. Education and government packages can be recorded as Other with confirmed P1/P2 features.

Microsoft Learn licensing reference ↗

Do you already operate a PKI for certificate-based authentication?

Walk out with a plan

Your plan reflects recorded answers and progress, including unresolved and deferred controls. Configuration examples require review of permissions, licensing, dependencies and placeholders. PowerShell bundles include an execution stop; read and edit them before deliberately running a selected section.