Utvikling / Feltnotat
Betinget tilgang som folk kan leve med
Identitetssikkerhet mislykkes når den kjemper mot brukerne sine. Start med risiko, innfør trinnvis, og behold en nødtilgang.
Dette feltnotatet publiseres på engelsk.
Multi-factor authentication everywhere is the right destination, but switching it on for everyone on a Monday morning is how you get a helpdesk queue and a quiet campaign to bypass it. Conditional access works better as a phased rollout ordered by risk.
Privileged accounts first
Global administrators, service principals with broad roles and anyone touching finance or customer data. These accounts get phishing-resistant MFA and compliant-device requirements before anyone else — the blast radius justifies the friction.
Then the everyday estate
Roll MFA to the rest of the organisation in groups, with a clear support path and a documented exception process. Report-only mode first: watch who would have been blocked for a week before enforcing anything.
Keep a break-glass
Two emergency accounts, long random passwords in sealed storage, excluded from every policy, monitored with alerts on any sign-in. They are the fire exit — never used in normal operation, checked regularly so they work when needed.
Review access on a rhythm
Access reviews every quarter for privileged roles, twice a year for everything else. People change teams, contractors leave, service principals outlive their purpose. The review is the control; conditional access is just the enforcement.
Further reading: Microsoft Entra conditional access documentation.