Conditional Access Design
Design it. Measure it. Change it safely.
Conditional Access is easy to configure into something that looks like a control and is not. Every weak estate looks the same from inside: the policies are individually correct, each decision was reasonable when somebody made it, and together they cover less than anybody believes. This course teaches the instruments that make the gap visible, from reading a verdict off the sign-in record to stating coverage as a number you can put in front of an auditor.
What you'll be able to do
Course overview
Conditional Access decides who gets into your tenant and under what conditions. The framework is simple to describe and the implementation is where organizations fail, because almost nothing about a policy tells you what it actually covers. The interface describes each condition by what it keeps. Its effect on your estate is what it releases, and that appears on no screen.
By the end you can answer the question this product makes surprisingly hard: what does this actually cover, and how would I know if that changed.
Who this course is for
Anyone responsible for who gets into a tenant and under what conditions. There is no minimum experience and no gatekeeping: every concept is explained at first use, so you can start here whether you have never opened the Conditional Access blade or have been maintaining policies for years.
What you'll learn
Six modules, working from how a decision is reached to what to do when a change has already locked people out.
Key course takeaways
Things you need to know
What are the prerequisites for this course?
None beyond working familiarity with a Microsoft 365 or Entra ID tenant. You do not need prior Conditional Access experience: the course builds the evaluation model from first principles before it asks you to design anything.
Do I need a tenant to follow along?
No, though it helps. Every module includes portal paths and checks you can run against a real tenant, and the reasoning stands on its own if you are reading without one.
What licensing does this assume?
Conditional Access requires Microsoft Entra ID P1. Some capabilities covered here need P2, Intune, or Microsoft 365 E5, and the course says so at the point each one appears rather than assuming you have everything.
Is this course current?
Every technical claim was verified against Microsoft's documentation at the time of writing. Conditional Access moves, and several capabilities covered here were in preview, so the references module tells you how to check whether anything has changed rather than leaving you to find out.
Usage rights and disclaimer
Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.
Policy examples, scenarios and figures are illustrative. Verify against your own tenant and against current Microsoft documentation before relying on any specific behavior, and treat the sign-in record as authoritative over any document, including this one.
Ridgeline Cyber is not affiliated with Microsoft. Product names are used descriptively.
Version and changelog
Version 1.0 · July 2026
Initial release. Six modules covering the evaluation engine, scope and assignment, conditions, controls, policy set design, and shipping and operating changes, with an operational reference and a references module.
Research-gated against Microsoft Learn, the Microsoft 365 Message Center and the Azure Architecture Center Conditional Access framework.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.