
When an organization decides it needs to improve security, the first instinct is often to buy something. A new endpoint agent, a new monitoring service, a new dashboard. Sometimes that is the right call. But in Microsoft environments, the most meaningful improvements usually come from configuring identity controls the organization already owns.
Identity is where most access decisions are made. If sign-in is weak, every other control is working from a compromised starting point.
Start with how people sign in
Multifactor authentication should be required for every account that can sign in, with stronger methods — authenticator apps, passkeys, or hardware keys — preferred over text messages where the organization can support them. Legacy authentication protocols that cannot perform MFA should be blocked. Administrative roles deserve stricter requirements than everyday accounts.
These are not advanced controls. They are the baseline, and in many tenants they are only partially in place: enforced for most users, with exceptions nobody remembers creating.
Conditional Access is a policy set, not a switch
Microsoft Entra Conditional Access lets an organization decide under what conditions access is granted — which users, which applications, from which devices and locations, with what level of assurance. It is powerful precisely because it is flexible, which also means it can drift into a collection of overlapping policies that are hard to reason about.
A useful Conditional Access design is one someone can explain. Each policy should have a clear purpose, a defined scope, and documented exclusions. Emergency access accounts should exist, be excluded deliberately, and be monitored. Changes should be tested in report-only mode before they are enforced.
Devices are part of identity
Knowing who is signing in is only half the question. Knowing whether they are signing in from a managed, compliant device is the other half. When Intune compliance feeds Conditional Access, the organization can require that sensitive applications are only reached from devices that meet its standards — without asking users to do anything differently day to day.
Ownership is the control that keeps the others working
Identity configuration is not a project that finishes. People join and leave, roles change, applications are added, and exceptions accumulate. The organizations that keep identity controls effective are the ones where someone owns reviewing them: who has administrative access, which exclusions still make sense, which guest accounts are still needed.
Additional security tooling can be valuable. It is most valuable on top of an identity foundation that is already configured, understood, and maintained.



