Cloud Security
A Conditional Access baseline that survives contact with users
Six policies that catch the common attacks without triggering an internal revolt.
Published by CloudFixies · 26 August 2025
The six
- 1. Block legacy auth. 2. Require phishing-resistant MFA for admins. 3. Require compliant device for M365 apps. 4. Block sign-in from high-risk countries. 5. Session-based sign-in frequency for privileged apps. 6. Break-glass account with strong controls.
The rollout
Report-only for two weeks before enforcement, per policy. Publish the change with the rollback plan on the same page.
◆ Takeaway
Six policies, report-only first, rollback plan visible. Then enforce.