Arendus / Praktikamärkus
Tingimuslik juurdepääs, millega inimesed saavad elada
Identiteediturvalisus ebaõnnestub, kui see võitleb oma kasutajatega. Alusta riskist, juuruta etappide kaupa ja hoia alles hädaolukorra juurdepääs.
See praktikamärkus on avaldatud inglise keeles.
Multi-factor authentication everywhere is the right destination, but switching it on for everyone on a Monday morning is how you get a helpdesk queue and a quiet campaign to bypass it. Conditional access works better as a phased rollout ordered by risk.
Privileged accounts first
Global administrators, service principals with broad roles and anyone touching finance or customer data. These accounts get phishing-resistant MFA and compliant-device requirements before anyone else — the blast radius justifies the friction.
Then the everyday estate
Roll MFA to the rest of the organisation in groups, with a clear support path and a documented exception process. Report-only mode first: watch who would have been blocked for a week before enforcing anything.
Keep a break-glass
Two emergency accounts, long random passwords in sealed storage, excluded from every policy, monitored with alerts on any sign-in. They are the fire exit — never used in normal operation, checked regularly so they work when needed.
Review access on a rhythm
Access reviews every quarter for privileged roles, twice a year for everything else. People change teams, contractors leave, service principals outlive their purpose. The review is the control; conditional access is just the enforcement.
Further reading: Microsoft Entra conditional access documentation.