At CyPro, we treat conditional access as the baseline control for any UK business tenant using cloud email and collaboration. Conditional access is realtime policy logic that allows, blocks or requires step‑up controls for sign‑ins and sessions based on user, device, location and risk; the National Cyber Security Centre explains how different multi‑factor authentication and conditional access methods provide materially different protection NCSC, 2025.
In the UK, phishing remains the most common cause of business breaches, so conditional access maps directly to breach reduction and regulatory expectations; see the Cyber security breaches survey 2025 for sector trends and the ENISA Threat Landscape 2025 for how adversaries operate across Europe.
- What it is: Conditional access is realtime policy logic that allows, blocks or enforces step‑up controls for sign‑ins and sessions.
- Why it matters: The National Cyber Security Centre and the Information Commissioner’s Office expect proportionate account controls and clear multi‑factor authentication practices NCSC, 2025, Information Commissioner’s Office, 2025.
- Where to start: Prioritise multi‑factor authentication, device compliance checks, named trusted locations and admin‑labelled policies for clarity.
- Quick win: Block legacy authentication and require multi‑factor authentication for all admin and cloud admin roles; this aligns with GOV.UK guidance on reducing credential misuse GOV.UK, 2025.
What is conditional access and why does it matter?
Conditional access is a set of access policies that grant, block or require extra controls for sign-ins and sessions based on signals such as user identity, device health, location and risk. It protects identities and sessions across cloud tenants like Microsoft Entra ID (Azure AD).
Where conditional access applies
Conditional access covers identities, applications, sessions and sign-ins inside cloud platforms and single sign-on systems. Organisations use conditional access to stop risky sign-ins, force multi-factor authentication (MFA) for sensitive apps, or block legacy authentication entirely. The policy scope is usually the identity provider and the app connectors that rely on it, for example Microsoft Entra ID with Exchange Online and SharePoint Online.
Regulatory and operational relevance in the UK
Under UK GDPR and ICO guidance, protecting account access with proportionate measures is expected; statements from the National Cyber Security Centre (NCSC) note that different MFA and conditional access methods provide materially different protection (NCSC, 2025). The UK Government’s Cyber Security Breaches Survey shows phishing remains the most common initial tactic, which conditional access can mitigate by blocking risky locations or forcing step-up controls (GOV.UK, 2025).
In our experience, conditional access is the baseline control for any UK business tenant using cloud email, collaboration or identity providers. It reduces the attack surface from credential misuse, improves incident triage by signalling risky sessions, and complements endpoint controls and identity hygiene programmes. When you design conditional access, include device state checks, named trusted locations and labelled administrative policies so policies map to real risk, not guesswork.
For teams unsure where to start, our Microsoft 365 security audit service reviews Conditional Access rules, sign-in logs and Entra ID configuration as a packaged step towards safer defaults.
How does conditional access work in practice?
Conditional access evaluates signals about the user, device, location, app and risk, then enforces a policy in real time: allow, block, require multi‑factor authentication or require a compliant device. In practice, conditional access ties these checks to identity providers and device management so controls fire during sign‑in or session initiation.
Primary signals and risk engines
Conditional access uses a set of signals: user identity and group, device health and compliance, IP address or location, the application being accessed, and risk detected by behavioural engines. Microsoft Entra ID (formerly Azure AD) and third‑party engines score sign‑in risk, enabling policies that react to unusual behaviour. The risk scores are often probabilistic, so policies must balance false positives with security needs. ENISA documents how conditional checks reduce successful credential misuse in cloud services, especially when combined with device checks and app restrictions (ENISA, 2025).
Policy actions and integration points
Typical policy actions are: require multi‑factor authentication, block access, require a compliant or hybrid‑joined device, require an approved client app, or apply session controls such as limited download or persistent cookie blocking. Conditional access integrates with Single Sign‑On (SSO), device management like Microsoft Intune, and identity protection services. In enterprise practice, tying conditional access to device management prevents sign‑ins from unmanaged endpoints and reduces lateral movement after credential compromise. Verizon’s 2025 Data Breach Investigations Report highlights how policies that combine MFA and device checks materially lower breach impact (Verizon DBIR, 2025).
Conditional access works by combining identity, device and risk signals into realtime policies so organisations can allow routine sign‑ins and block or harden risky ones.
In our experience configuring tenant controls, sensible policy layering wins: a baseline policy that requires multi‑factor authentication for all admin roles, a device‑compliance policy for privileged apps, and location‑based blocks for high‑risk geographies. For UK organisations, start with Entra ID policy templates, validate them in a pilot group, then expand coverage while monitoring sign‑in logs and risk alerts.
For practical help auditing these settings we provide an Azure security assessment and configuration review that examines Entra ID, Conditional Access and device management controls against CIS benchmarks.
Who in the UK needs conditional access now?
Organisations with cloud identities, Microsoft 365 tenants or regular remote workers should implement conditional access now. It is the baseline control that reduces credential misuse and helps meet UK GDPR and ICO expectations for reasonable technical measures.
Segment profiles
Small firms that handle sensitive personal data, mid‑market financial services and legal firms, and regulated entities under NIS2 or the Digital Operational Resilience Act (DORA) all need conditional access. In the UK, the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC) recommend policy‑based access controls for cloud services to reduce phishing and account takeover risk. Organisations using Microsoft 365 can protect mailboxes and admin accounts by applying device checks, location rules and risk‑based step up authentication with conditional access.
Practical thresholds for action
If you have more than a handful of cloud identities, use third‑party SaaS, or allow remote admin access, move from basic Multi‑Factor Authentication (MFA) to policy‑based conditional access. Forrester found the Zero Trust trend drives demand for conditional controls in 2025, especially where legacy VPNs or broad admin privileges exist (Forrester, 2025). The UK Data Use and Access Act 2025 and its guidance make clear that technical access controls are part of compliance for some regulated processing (GOV.UK).
What this means for your IT team
Start with a pilot: protect high‑value groups, admin roles and cloud apps, then expand. We recommend pairing conditional access with device compliance checks and logging so incidents can be triaged. If you use Microsoft 365, consider a tenant security audit to validate policies and gaps before a wide rollout (Microsoft 365 security audit).
What are the seven baseline conditional access policies every tenant needs?
Ship seven concrete conditional access policies that protect admins, require multi-factor authentication for risky sign-ins, block legacy auth, enforce device compliance, restrict access by location, harden high‑risk apps, and apply session controls, with documented break‑glass procedures and logging.
The seven policies, listed
1. Admin protection policy. Require dedicated admin accounts, enforce strong MFA and block admin sign‑ins from unmanaged devices. This prevents privilege abuse and is the most important single restriction for cloud tenants.
2. Require MFA for all interactive sign‑ins. Enforce multi‑factor authentication for human users, especially when sign‑ins are from new devices or unfamiliar locations. The National Cyber Security Centre’s guidance emphasises how different MFA and conditional access methods offer materially different protection, so choose methods that resist push‑bombing and SIM swap fraud (NCSC, 2025).
3. Block legacy authentication. Disable protocols that do not support modern authentication, since legacy auth is a frequent route for credential stuffing and scripted abuse.
4. Device compliance policy. Require enrolled and compliant devices (Intune or equivalent) before granting access to sensitive apps, so device posture (patch level, encryption) becomes part of the decision.
5. Sign‑in risk policy. Use risk signals from your identity provider to step up authentication or block access on high‑risk sign‑ins, limiting account takeover impact.
6. App protection / minimum permissions policy. Restrict which client apps and service principals can access high‑value data, and require approved apps for access to sensitive workloads.
7. Session and access time controls. Apply session length limits, require reauthentication for privileged tasks and block access outside business hours where appropriate.
Break‑glass, logging and testing
Every policy must include a break‑glass account and a documented emergency process, with the account stored in an access vault and monitored. Log all policy decisions and sign‑in events centrally so your SOC or monitoring tool can triage incidents; the NCSC annual review shows detection and response rely on good logging and telemetry (NCSC, 2025).
In our experience, conditional access policies work best when rolled out in a controlled pilot, applied to high‑risk groups first, and paired with device compliance checks and monitoring. If you use Microsoft 365, consider an Office 365 security monitoring engagement to keep sign‑in alerts watched 24/7 after you deploy policies (Office 365 security monitoring) and read our explainer on how we scope and run tenant reviews (How it works).
How much does conditional access cost in the UK? £ ranges and licence questions
Direct answer: costs usually include identity licensing, device management, and one-off professional setup; expect £1 to £6 per user per month for basic controls and £4 to £15 per user per month where advanced features and device checks are required in 2026.
Licence fees, device management and consultancy are the three buckets that drive total cost for conditional access, with implementation effort pushing small projects into mid-four figures and enterprise rollouts into low five figures.
Licence tiers and what they buy you
Microsoft Entra ID (formerly Azure AD) licence tiers are the common starting point for UK organisations: Free, P1 and P2. P1 covers policy-based access controls and basic risk signals, P2 adds risk-based conditional access, identity protection and privileged identity features. If you do not use Microsoft Identity, vendor licences from Okta or Ping will be roughly comparable.
Organisations that need step-up authentication, risky sign-in detection and automated blocking usually require P2 or equivalent, which explains the higher per-user band in large deployments. Consult the vendor licence pages for exact SKU pricing for 2026 and local reseller discounts.
Implementation and device management costs
Device checks require a device management platform such as Microsoft Intune, Jamf or a Mobile Device Management (MDM) product; expect additional costs of £2 to £8 per device per month for management and compliance reporting. Professional services for scoping, pilot policies and break-glass planning typically run from £2,000 to £12,000 depending on complexity and number of apps protected.
| Organisation size | Typical licence cost (per user / month, 2026) | One-off implementation fee |
|---|---|---|
| Small (≤50 staff) | £1 to £4 | £2,000 to £5,000 |
| Mid-market (50 to 500 staff) | £3 to £8 | £4,000 to £10,000 |
| Large (500+ staff) | £6 to £15 | £8,000 to £25,000 |
Where device posture, network location and app risk are enforced, expect the higher end of the licence and service ranges. The ENISA consolidated activity report 2025 notes growing uptake of risk-based access controls across Europe, which is driving richer vendor features and licence tiers. The UK Information Commissioner's Office guidance on recent data and access changes highlights that stronger access controls reduce breach risk and compliance exposure, which factors into total cost calculation; see the ICO guidance on the Data Use and Access Act 2025.
At CyPro, we advise starting with a pilot protecting admin roles and high-risk applications, then extend policies. For Microsoft tenants, a focused tenant assessment followed by a scoped pilot keeps professional fees predictable; see our FreshWave case study for an example of staged delivery FreshWave security assurance.
How does conditional access differ from MFA and network controls?
Conditional access is policy-based access control that grants or blocks sessions based on context such as user, device state, location and risk score. MFA is an authentication factor, and network controls are perimeter or path controls that restrict network traffic rather than individual sessions.
Scope and enforcement
Conditional access operates at the session and service level, enforcing policies when users try to access cloud apps or resources, while multi-factor authentication (MFA) only proves identity at sign-in and network controls manage traffic flows between hosts or subnets.
The distinction matters because conditional access can combine signals the organisation already has, such as device compliance from Microsoft Intune or endpoint posture from an EDR product, and react in real time. The 2025 Data Breach Investigations Report (Verizon) highlights that credential-based attacks remain a major breach cause, so layering controls reduces risk.
| Dimension | Conditional access | MFA | Network controls |
|---|---|---|---|
| Scope | Session and app policies, context aware | Authentication factor at sign-in | Traffic filtering and segmentation |
| Typical cost | Often included with identity platforms, or licensing uplift | Low per-user or built into identity licensing | Device or appliance cost, VPN or ZTNA licensing |
| Time-to-value | Weeks for pilot policies | Days to enable broadly | Weeks to months for segmentation projects |
Practical overlap and gaps
Conditional access fills gaps MFA and network controls leave. MFA prevents simple credential replay, but conditional access applies contextual rules after authentication, for example forcing reauthentication, blocking access from risky locations, or requiring a compliant device. Network controls protect on-prem systems and east-west traffic but cannot see cloud app session attributes.
For UK organisations the implication is clear: use conditional access alongside MFA and network controls, not instead of them. Conditional access ties identity, device management and risk signals together so teams can set policies that match business risk. If you want a formal tenant review that includes Conditional Access configuration, our Microsoft 365 audit explains common misconfigurations in detail and what to fix next (Microsoft 365 security audit).
For further reading on how to architect policy decisions and platform selection, Gartner's research on zero trust platforms helps map conditional access to a wider zero trust plan (Gartner).
When should you implement conditional access and how do you choose a policy supplier?
Implement conditional access as soon as you rely on cloud identities, remote access or bring-your-own-device setups; prioritise high-risk apps and admin accounts first and buy a supplier that can test, template and hand policies over. In the UK this usually means starting during a cloud migration or when staff number or remote access rises.
Start with protecting admin and sensitive SaaS apps, pilot policies for a user group, then expand; choose a supplier who can document, test and hand over policies without locking you in.
When to prioritise rollout
Implement conditional access immediately for admin accounts, remote sign-ins from unfamiliar locations, and any app that holds personal or financial data. Evidence from the ENISA Threat Landscape shows credential misuse remains a root cause of breaches, so protecting identities reduces exposure (ENISA, 2025). Conditional access combined with multi-factor authentication is the practical control that stops many common attack patterns.
How to choose a policy supplier
Choose a supplier on four practical criteria: Microsoft Entra ID experience, policy templates you can reuse, test and rollback processes, and UK-based support. Suppliers should demonstrate end-to-end delivery: discovery, pilot, live rollout, and scripted handover. The 2025 Data Breach Investigations Report highlights that many breaches involve compromised credentials, so pick a supplier who understands how conditional access interacts with phishing-resistant methods (Verizon DBIR, 2025).
Ask suppliers for these deliverables: a matrix of policies by app and user group, test scripts and rollback steps, an outage and failure mode plan, and runbooks for break-glass access. Licence advice matters: many Microsoft 365 plans require Entra ID Premium P1 or P2 for specific controls, so a supplier who can map policies to licences saves money.
At CyPro, we build policies in a sandbox, run a two-week pilot on a real user cohort, and hand over a policy pack with automated tests and rollback scripts. We recommend rolling conditional access incrementally, logging results, and treating exception approvals as temporary with automated expiry.
Frequently asked questions
Do I need conditional access if I already use MFA?
Key fact: Multi-Factor Authentication (MFA) verifies who signs in, while conditional access makes contextual policy decisions about when and how that access is allowed. Conditional access matters where legacy protocols, unmanaged devices or high-risk sign-ins bypass MFA. For UK tenants, a simple rule is: keep MFA and add conditional access to cover conditional factors such as device health, location and client apps.
How long does it take to implement baseline conditional access policies?
Key fact: Typical implementation time varies by size: days for small tenants, and two to six weeks for mid-market organisations with phased testing. Workstreams include discovery, pilot, staged enforcement, monitoring and an incident drill. Timelines depend on licence availability and device management coverage, so check your licence entitlements and endpoint management before scheduling enforcement.
Can conditional access be outsourced to a managed service?
Key fact: Organisations can outsource conditional access policy management, but policy design, emergency break-glass controls and governance should remain internal. Ask a managed provider for clear policy ownership, log access, emergency access procedures and contractual Service Level Agreements (SLA). Also confirm integration with your Security Operations Centre (SOC) monitoring and incident response processes.
Will conditional access meet UK GDPR and ICO expectations?
Key fact: Conditional access provides technical and organisational measures that support compliance with the UK General Data Protection Regulation (UK GDPR) and Information Commissioner’s Office (ICO) guidance, but it is not a legal cure-all. Map conditional access to your risk assessment, document decisions and consider a Data Protection Impact Assessment (DPIA) where sign-in controls affect personal data processing.
What is the ROI of conditional access for a mid-market firm?
Key fact: Return on investment comes from fewer account compromises and faster containment, which reduce incident costs. Estimate ROI with a simple formula: expected percentage reduction in breach likelihood times average incident cost equals expected annual saving. Measure outcomes after deployment by tracking account compromise rates, mean time to detect and incident remediation costs.