Développement / Note de terrain
Un accès conditionnel avec lequel on peut vivre
La sécurité des identités échoue quand elle entre en conflit avec ses utilisateurs. Commencez par le risque, déployez par étapes et gardez un accès de secours.
Cette note de terrain est publiée en anglais.
Multi-factor authentication everywhere is the right destination, but switching it on for everyone on a Monday morning is how you get a helpdesk queue and a quiet campaign to bypass it. Conditional access works better as a phased rollout ordered by risk.
Privileged accounts first
Global administrators, service principals with broad roles and anyone touching finance or customer data. These accounts get phishing-resistant MFA and compliant-device requirements before anyone else — the blast radius justifies the friction.
Then the everyday estate
Roll MFA to the rest of the organisation in groups, with a clear support path and a documented exception process. Report-only mode first: watch who would have been blocked for a week before enforcing anything.
Keep a break-glass
Two emergency accounts, long random passwords in sealed storage, excluded from every policy, monitored with alerts on any sign-in. They are the fire exit — never used in normal operation, checked regularly so they work when needed.
Review access on a rhythm
Access reviews every quarter for privileged roles, twice a year for everything else. People change teams, contractors leave, service principals outlive their purpose. The review is the control; conditional access is just the enforcement.
Further reading: Microsoft Entra conditional access documentation.