Tag
#conditional-access
4 posts tagged #conditional-access.
-
Field Note · Jul 6, 2026 · Colten Anderson
Your break-glass account probably can't sign in anymore. Test it this quarter.
Mandatory Entra MFA now gates the admin portals for every account, break-glass included. Here's how to audit, fix, and quarterly-test the emergency account you've never actually used.
-
Analysis · Jul 5, 2026 · Colten Anderson
Nobody broke your MFA. They took the token it handed out.
Across four theft vectors and a half-dozen named campaigns, the pattern is the same: the session cookie, refresh token, or Entra PRT minted after MFA is the live credential, and the controls that guard the login don't guard the session.
-
Field Note · Jul 5, 2026 · Colten Anderson
The Intune device that passes Conditional Access without ever being checked
Intune's default scores an unpoliced device as compliant, and Conditional Access opens the gate for it. Here's how to audit the gap and flip the switch without locking anyone out.
-
Analysis · Jun 5, 2026 · Colten Anderson
Your Azure CLI session has an MFA exemption you never asked for
Two Entra Conditional Access changes land in the same fortnight, and they're the lead evidence in a longer story: Microsoft is closing the identity opt-outs orgs have leaned on for years.