• SituationConditional access already deployed · mix of enforced, report-only, and leftover test policies · privileged roles assigned
  • RiskA policy that only reports does not stop the sign-in · admin and device controls weaker than their names · licenses that do not match the roles
  • OutcomeEnforce-or-retire order · privileged role and license picture · test policies called out before anyone turned them on by accident

The situation

The tenant was not wide open. Multifactor authentication covered administrators and everyday Microsoft 365 sign-in. Risk-based policies were present. Legacy authentication was blocked. From a distance the program looked finished.

A closer read of policy state told a different story. Stronger authentication for administrators, tighter rules for unmanaged devices, and at least one insider-risk control were enabled for reporting and not enforced. Test policies sat beside production ones. Privileged role holders, Global Administrators among them, had never been lined up against the licenses the intended controls require. Report-only feels like progress. It does not change what an attacker, or a careless sign-in, is allowed to do.

What we did

  • Exported the conditional access set and sorted every policy: enforced, report-only, or disabled
  • Reviewed admin, user, and sign-in risk policies for who they covered, not just what they were named
  • Matched privileged role assignments to the licenses those controls depend on
  • Marked overlaps and test policies that should be retired, not enforced by mistake
  • Wrote an enforce order: administrators first, then device and session limits, with a rollback note on each change

Results

The organization could see which controls were real and which were still drafts. Privileged access was a reviewed list, not a side spreadsheet. Nothing in the engagement pretended that flipping a report-only policy to On is free of helpdesk pain. The sequence and the rollback notes were the point.

Client identity is withheld. The pattern is one we repeat: enforce the control you already wrote, or delete it. A report-only policy is a draft.

Related

See our Microsoft Azure and Network Security practices, or contact us if conditional access is “on” and nobody has checked which policies actually enforce.

Ready to talk through the next step?

Projects, managed services, or an honest read on your environment. You reach a principal consultant.