hands-on lab

Using Conditional Access Policies to Enable Microsoft Entra ID Multi-Factor Authentication

Difficulty: Beginner
Duration: Up to 1 hour and 15 minutes
Students: 685
Rating: 4/5

Microsoft has currently disabled new registrations for the MS 365 Dev program. For the time being, please treat the lab as read-only or bring your own MS 365 account. Thank you for your understanding.

On average, students complete this lab in10m
Get guided in a real environmentPractice with a step-by-step scenario in a real, provisioned environment.
Learn and validateUse validations to check your solutions every step of the way.
See resultsTrack your knowledge and monitor your progress.

Description

Conditional access is a modern security mechanism that emphasizes identity as a security layer. It brings together signals from various sources such as the device a user attempts authentication from or the location from which they're attempting to authenticate and uses these signals to make a decision and enforce a policy. Microsoft Entra ID Conditional Access policies are simple if-then statements that work to verify every attempt at authentication.

In this lab, you will set up and test a conditional access policy to trigger a multi-factor authentication request.

Note: Due to this lab requiring the creation of a Microsoft 365 organization with an Admin Center, if you don't already have one you will need to provide a mobile phone number to pass the account creation process.

Learning Objectives

Upon completion of this lab, you will be able to:

  • Create a custom conditional access policy in Microsoft Entra ID
  • Test against target users whether the policy works

Intended Audience

  • Candidates studying for the SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) Certification exam

Prerequisites

  • Familiarity with Microsoft Entra ID is recommended, but not necessary

Environment before

Environment after

Covered topics

Hands-on Lab UUID

Lab steps

Setting Up A Microsoft 365 Developer Account
Creating a Conditional Access Policy
Testing Conditional Access Policy to Trigger Multi-Factor Authentication Prompt