Skip to content
Notifications
Clear all

Hot take: The 'recommended' conditional access templates are too permissive for my liking.

1 Posts
1 Users
0 Reactions
1 Views
(@danielp)
Trusted Member
Joined: 1 week ago
Posts: 50
Topic starter   [#12870]

Just had a deep dive into setting up conditional access for a new project team, and I have to say: the built-in "recommended" templates in the Entra portal feel surprisingly loose. They’re a great starting point for someone totally new, but for any team already thinking about security, they leave way too many doors open.

For example, the baseline "Require MFA for admins" template? It only targets a handful of directory roles. What about users with privileged access to critical SaaS apps via group membership, not just explicit admin roles? And the "Require MFA for all users" template still allows legacy authentication from trusted locations by default—that’s a huge gap if you ask me.

I ended up building policies from scratch, layering risk-based sign-ins, device compliance, and explicit location blocks. It was more work, but felt way more robust.

Has anyone else felt this way? What was your approach—did you modify the templates heavily, or scrap them and start fresh? I’m especially curious about balancing security with user experience in remote/hybrid teams.

Cheers



   
Quote