A sixteen-policy Conditional Access baseline where device compliance is the gate, personal phones get app-level protection instead of enrollment, and admin rights only exist while they're being used. Shipped report-only first — nobody was locked out by surprise.
Moving an estate to cloud management (written up separately) only pays off if the cloud is where access decisions get made too. Once Intune knows whether a device is compliant, that signal becomes the thing standing between a stolen credential and the company's data — not the network it happens to be sitting on.
So the access layer got rebuilt around four questions asked in order: who is signing in, what are they signing in from, what can they do once they're in, and how long do they get to keep it. Every rule that answers one of those questions is a numbered policy with a stated purpose, so it can be audited, explained to an auditor or an executive, and reverted in isolation when it turns out to be wrong.
An unnumbered Conditional Access estate becomes folklore within a year — nobody remembers which rule blocks what, so nobody touches any of them. Numbering them turns the tenant into a register: each policy has an ID, a single job, and a documented exclusion set, and a change request can name exactly what it wants changed.
The usual BYOD offer is a bad trade for both sides: enroll your personal phone and hand IT a management channel over it, or get no access at all. App protection policies split the difference. The policy travels with the app, not the device — corporate data lives in an encrypted app container, requires a PIN to open, and can't be copied out into personal apps, saved to personal storage, or backed up to a personal cloud account.
When someone leaves or loses a phone, the corporate container is wiped selectively. Their photos, messages, and personal apps are never in scope, which is exactly what makes the policy acceptable to the people carrying the phones. Conditional Access enforces it: on mobile platforms, access requires an approved client app carrying the policy, so there's no path around it through a browser or a third-party mail client.
Standing admin assignments are the quiet risk in most tenants: a role granted once for a project, still live three years later, sitting on an account that reads email all day. Privileged Identity Management flips it — roles are held as eligible, and activating one requires a justification, produces an audit record, and expires by itself.
The part that makes it more than paperwork is the authentication context. Activation is bound to its own context with a stricter Conditional Access rule than everyday sign-in, so stepping up to admin means proving identity again at a higher bar, on a compliant device, at that moment — not riding a session token minted hours earlier over coffee.
The weakest link in most MFA deployments is the fallback method. SMS and voice codes are phishable and SIM-swappable, and Microsoft has set an end date for them as authentication methods — which turns a security improvement into a migration with a deadline attached.
The move is to phishing-resistant credentials: Windows Hello for Business on corporate machines, passkeys in Microsoft Authenticator for phones, and a passphrase policy that stops fighting users with quarterly expiry rules that never made anyone safer. I packaged the whole rollout as a SharePoint site — enrollment walkthroughs, per-platform guidance, and the policy change explained in plain language — because a credential migration is a communications project wearing an engineering costume.
Conditional Access is the one place where a good idea deployed badly takes the whole company offline at 8am. Every policy in the baseline went through the same four stages before it enforced anything.
The through-line with the rest of my work is the same one as always: the answer to a security problem is a system that holds the line by itself, not a policy document asking people to be careful.
I'm open to Principal Cloud / EUC Architect conversations, and to work at organizations building things that matter — infrastructure, security, or the mission itself.