ডেভেলপমেন্ট / ফিল্ড নোট
এমন কন্ডিশনাল অ্যাক্সেস, যা নিয়ে মানুষ থাকতে পারে
পরিচয় নিরাপত্তা ব্যর্থ হয় যখন তা ব্যবহারকারীদের সঙ্গে লড়ে। ঝুঁকি দিয়ে শুরু করুন, ধাপে ধাপে চালু করুন, আর একটি ব্রেক-গ্লাস পথ রাখুন।
এই ফিল্ড নোটটি ইংরেজিতে প্রকাশিত।
Multi-factor authentication everywhere is the right destination, but switching it on for everyone on a Monday morning is how you get a helpdesk queue and a quiet campaign to bypass it. Conditional access works better as a phased rollout ordered by risk.
Privileged accounts first
Global administrators, service principals with broad roles and anyone touching finance or customer data. These accounts get phishing-resistant MFA and compliant-device requirements before anyone else — the blast radius justifies the friction.
Then the everyday estate
Roll MFA to the rest of the organisation in groups, with a clear support path and a documented exception process. Report-only mode first: watch who would have been blocked for a week before enforcing anything.
Keep a break-glass
Two emergency accounts, long random passwords in sealed storage, excluded from every policy, monitored with alerts on any sign-in. They are the fire exit — never used in normal operation, checked regularly so they work when needed.
Review access on a rhythm
Access reviews every quarter for privileged roles, twice a year for everything else. People change teams, contractors leave, service principals outlive their purpose. The review is the control; conditional access is just the enforcement.
Further reading: Microsoft Entra conditional access documentation.