Blog & Guides
Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.
2 results for “conditional access baseline” · Clear
Passkeys by Default and the Retirement of Microsoft SMS and Voice MFA: The Entra Migration Playbook
Microsoft Entra ID is making passkeys the default sign-in experience and retiring Microsoft-provided SMS and voice authentication. Two dates matter: on 1 September 2026 passkeys are auto-enabled for every user still on SMS or voice and a Microsoft-managed registration campaign starts nudging them; on 1 February 2027 Microsoft-provided SMS and voice telecom delivery is retired, and after that any user whose only MFA method is SMS or voice hits a blocking passkey-registration prompt with no opt-out. This playbook covers who is in scope, how to find your exposed users, how to move them to passkeys, when a customer-managed telecom provider is worth it, the temporary Graph opt-out and its limits, and how it all ties into your Conditional Access baseline. Dates and behaviours validated against Microsoft Learn, August 2026.
Conditional Access Baseline Policies Every Microsoft 365 Tenant Needs in 2026
Every Microsoft 365 tenant should run a baseline of roughly eight to ten Conditional Access policies — block legacy authentication, require MFA for all users, phishing-resistant MFA for admins, compliant or managed devices, block device code flow, sign-in and user-risk policies, session controls, guest MFA, and a break-glass exclusion group — deployed in report-only first, piloted with a ring group, then enforced. This guide gives the named set, the safe rollout order, the P1/P2 licensing reality, the enforcement changes that landed in June and July 2026, and the production gotchas that lock teams out of their own tenant.