Conditional Access is the single highest-leverage security control inside Microsoft Entra. These eight baseline policies form the 2026 minimum for any Texas SMB running Microsoft 365.
Conditional Access is the most powerful identity control inside Microsoft Entra ID — and the most underconfigured. Microsoft's 2025 Digital Defense Report found that over 99% of identity attacks could be blocked by basic Conditional Access policies that take an administrator under an hour to configure. Yet a majority of Texas SMBs still run Entra in default-allow mode.
This is the eight-policy baseline a Houston M365 managed services provider deploys on day one of every engagement.
Out of the box, an Entra tenant accepts logins from anywhere in the world, on any device, with only a password and a single MFA factor (often SMS). After 2024-2025, that posture is indefensible. Adversary-in-the-middle phishing, push-bombing, and SIM swap attacks routinely defeat baseline MFA. Conditional Access closes those gaps.
Legacy auth protocols (IMAP, POP, SMTP AUTH, MAPI/HTTP, EWS) bypass MFA entirely. Modern attackers exploit them as a primary entry vector. Block them tenant-wide. Microsoft now blocks new tenants by default, but every tenant created before 2023 needs the explicit Conditional Access rule.
Yes, all of them. Service accounts get migrated to managed identities or certificate auth — never passwords without MFA. Break-glass accounts get stored hardware keys in a fireproof safe. Everyone else gets phishing-resistant MFA via Microsoft Authenticator with number matching, or hardware FIDO2.
Global Admin, Privileged Role Admin, Application Admin, Conditional Access Admin, Authentication Policy Admin, Helpdesk Admin, Security Admin, Privileged Authentication Admin — every privileged role requires FIDO2 or Windows Hello for Business, not push notifications. The cost is $40 per administrator and roughly 30 minutes of enrollment time. The benefit is immunity to AiTM phishing for the highest-value accounts in your tenant.
Even if an attacker captures a user's session cookie via AiTM, replaying it from an unmanaged device fails. This policy ties access to device posture managed by Intune. For Texas SMBs that already use Intune-managed M365 deployments, this policy is configuration-only — no additional licensing.
Most Texas SMBs do no business in Russia, North Korea, China, Iran, Belarus, or Cuba. Block sign-ins from those geographies entirely. Honest mistakes from a traveling employee are easier to handle than account compromise from a state-sponsored attacker.
Layered with Policy 3: privileged role activations require both FIDO2 and an Intune-compliant device. Combined, these two controls make administrator account takeover meaningfully harder for any attacker.
Entra ID Protection (P2 license tier) generates real-time risk scores per sign-in based on impossible travel, anonymous IP, malware-linked IP, password spray patterns, and leaked credentials. Block sign-ins flagged High Risk. For SMBs without P2, P1 still surfaces the signals — manual review of weekly risky sign-in reports is the workaround.
Default Entra session tokens are valid for 90 days. For most users that is far too long. Set sign-in frequency to 24 hours for general users, 4 hours for administrators on browsers, and require re-authentication on sensitive operations (password change, MFA registration, payment portal access).
For full-stack M365 hardening context, see our MFA bypass guide, our PAM service overview, and the 2026 Texas SMB Benchmark Report.
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.