Security Ninja

Conditional Access Dojo

Conditional Access is the bouncer for your Microsoft 365 tenant, but the policy screen assumes you already know kung fu. This dojo doesn't. Answer eight questions about your setup, then work through the belts. Every policy comes with the risk it reduces or helps detect, the MITRE ATT&CK techniques behind it, and the exact clicks to build it. Mark your progress and walk out with a deployment plan.

Built on the shoulders of Joey Verlinden's Conditional Access Baseline ↗ — many thanks, Joey, for the incredible contribution to the community.

Recorded progress
0 / 1000
Current Rank
No belt yet
0 enforced 0 report-only 0 in scope

User-recorded progress; not tenant-verified.

Step 0 — Break-glass accounts (before you touch anything)

A misconfigured policy can lock every admin out — including you. Break-glass accounts are the mat you land on. Confirm recovery and authentication dependencies before enforcement:

Everything else about these accounts — creating them, credentials, monitoring, and optionally using restricted management after validating recovery and governance compatibility — is owned by the Privileged Access Dojo, so the guidance lives in exactly one place. Microsoft's reference: Manage emergency access accounts ↗

Size up your environment

A few questions. The dojo tailors the policy set to what you actually run — and tells you honestly when a policy isn't for you.

Which licences do you hold? Select all that apply.
More products and add-ons

Check assignments for each affected user, cloud and feature. Education and government packages can be recorded as Other with confirmed P1/P2 features.

Microsoft Learn licensing reference ↗

Do you manage devices with Intune?

Do external guests collaborate in your tenant?

What phones/tablets reach work email or Teams?

Does anyone manage Azure resources?

How far do you want to push passkeys / FIDO2?

Do you want to go passwordless?

What do staff work on?

Do you use Microsoft Entra agent identities?

Have you confirmed agent-risk licensing and preview availability?

Walk out with a plan

Your plan reflects recorded answers and progress. The JSON bundle is an array of report-only Graph examples with placeholder IDs. Validate each policy individually against the documented API or supported portal format before import; bundle-array import compatibility has not been verified.