Designing a Conditional Access baseline you can defend
A Conditional Access baseline is not a checklist of every available toggle. It’s a small set of policies that you can reason about, document, and explain to an auditor in five minutes.
I start with seven policies. Block legacy authentication. Require MFA for all users. Require a compliant device for Microsoft 365. Block sign-ins from named high-risk locations. Require phishing-resistant MFA for admin roles. Apply sign-in risk gates. Disable persistent browser sessions on unmanaged devices.
Everything else — app-specific exceptions, vendor access, BYOD — is built on top of this floor, not woven into it. The result is a baseline you can change with confidence, because each policy has a clear purpose and a clear blast radius.