Conditional Access Design

Design it. Measure it. Change it safely.

Conditional Access is easy to configure into something that looks like a control and is not. Every weak estate looks the same from inside: the policies are individually correct, each decision was reasonable when somebody made it, and together they cover less than anybody believes. This course teaches the instruments that make the gap visible, from reading a verdict off the sign-in record to stating coverage as a number you can put in front of an auditor.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 8 CPE Credits

What you'll be able to do

Read an access decision from the sign-in record rather than reasoning about it, naming the policy that fired and the requirement that was not met
State what a policy actually covers as a number you can defend, including the populations an assignment cannot express at all
Choose conditions knowing what each one releases, and tell a signal that asserts something from one that merely reports it
Demand a specific quality of proof with authentication strength, and know which populations and controls it cannot reach
Structure a policy set around populations rather than controls, with names that let somebody else review and retire a policy
Protect an operation rather than a whole application using authentication contexts, so a strong requirement lands where it belongs
Ship a change through simulation, rehearsal and a staged rollout, and recover when one has already locked people out
ARC404 | Premium tier | 6 modules across 4 phases | 6–8 hours at your own pace | 8 CPE credits | Updated July 2026
Course Agenda View Course ModulesHide Course Modules

Course overview

Conditional Access decides who gets into your tenant and under what conditions. The framework is simple to describe and the implementation is where organizations fail, because almost nothing about a policy tells you what it actually covers. The interface describes each condition by what it keeps. Its effect on your estate is what it releases, and that appears on no screen.

Two phases, and why a policy that never matched a request is not a policy that passed
Coverage as arithmetic: include, minus exclude, minus what the selection cannot express at all
Which signals assert something, and which merely report what the requester claimed
A policy set structured around populations, with names that let somebody else review and retire a policy

By the end you can answer the question this product makes surprisingly hard: what does this actually cover, and how would I know if that changed.

Who this course is for

Anyone responsible for who gets into a tenant and under what conditions. There is no minimum experience and no gatekeeping: every concept is explained at first use, so you can start here whether you have never opened the Conditional Access blade or have been maintaining policies for years.

Identity engineers and security architects designing an access layer, from an empty tenant or an inherited one
SOC analysts who keep meeting Conditional Access in sign-in logs and want to read a verdict properly
Microsoft 365 administrators who inherited an estate nobody can currently explain
Consultants who need a coverage figure they can defend in front of a client or an auditor

What you'll learn

Six modules, working from how a decision is reached to what to do when a change has already locked people out.

Read an access decision from the sign-in record rather than reasoning about it, naming the policy that fired and the requirement that was not met
State what a policy covers as a number you can defend, including the populations an assignment cannot express
Choose conditions knowing what each one releases, and tell a signal that asserts something from one that reports a claim
Demand a specific quality of proof with authentication strength, and know which populations and controls it cannot reach
Structure a set around populations, and protect an operation rather than a whole application with authentication contexts
Ship a change through simulation, rehearsal and a staged rollout, and recover when one has already gone wrong

Key course takeaways

A coverage statement per population: include minus exclude minus what the selection cannot express, written as a sentence that survives a follow-up question
A layered policy set: a baseline that reaches everybody, persona layers above it, and step-up access on the operations that warrant it
An exclusion register with an owner, a reason and a review date on every entry, because the exclude side carries none of those on its own
A break-glass specification and a deployment sequence, so a change can be shipped and reversed without depending on one person being reachable

Things you need to know

What are the prerequisites for this course?

None beyond working familiarity with a Microsoft 365 or Entra ID tenant. You do not need prior Conditional Access experience: the course builds the evaluation model from first principles before it asks you to design anything.

Do I need a tenant to follow along?

No, though it helps. Every module includes portal paths and checks you can run against a real tenant, and the reasoning stands on its own if you are reading without one.

What licensing does this assume?

Conditional Access requires Microsoft Entra ID P1. Some capabilities covered here need P2, Intune, or Microsoft 365 E5, and the course says so at the point each one appears rather than assuming you have everything.

Is this course current?

Every technical claim was verified against Microsoft's documentation at the time of writing. Conditional Access moves, and several capabilities covered here were in preview, so the references module tells you how to check whether anything has changed rather than leaving you to find out.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

Policy examples, scenarios and figures are illustrative. Verify against your own tenant and against current Microsoft documentation before relying on any specific behavior, and treat the sign-in record as authoritative over any document, including this one.

Ridgeline Cyber is not affiliated with Microsoft. Product names are used descriptively.

Version and changelog

Version 1.0 · July 2026

Initial release. Six modules covering the evaluation engine, scope and assignment, conditions, controls, policy set design, and shipping and operating changes, with an operational reference and a references module.

Research-gated against Microsoft Learn, the Microsoft 365 Message Center and the Azure Architecture Center Conditional Access framework.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.