Conditional Access & Risk Policies
Apply sign-in conditions based on context and assessed risk, not credentials alone.
Overview
Remote working, internet-accessed applications and sign-ins from unfamiliar locations or devices can expose weaknesses in blanket rules based on credentials alone. Overlapping policies and inconsistent exceptions can also lead to legitimate users being blocked or make it difficult to explain why access was allowed or denied.
The solution evaluates sign-in context and risk before access is granted. It defines policy criteria, exclusions and their intended purpose, and supports review of overlapping policies and their effects. Higher-risk sign-ins can be blocked or required to meet additional conditions, while IT teams can trace an access outcome to the policies that applied.
What this solution helps you achieve
Reduce identity-based risk
Minimise the likelihood and impact of breaches caused by compromised, excessive or misused identities.
Secure authentication without friction
Improve authentication security while keeping access friction low for end users.
Consistent authentication requirements
Authentication requirements are applied consistently where intended.
Traceable access decisions
IT teams can identify which policies affected an access outcome.
Products for this solution
Explore options for this solution. The right choice depends on your environment, requirements and existing tools. We can help you assess which products fit and where they complement one another.