Knowledge Base

Blog & Guides

Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.

2 posts

2 results for “conditional access baseline” · Clear

Article Aug 28, 2026

Passkeys by Default and the Retirement of Microsoft SMS and Voice MFA: The Entra Migration Playbook

Microsoft Entra ID is making passkeys the default sign-in experience and retiring Microsoft-provided SMS and voice authentication. Two dates matter: on 1 September 2026 passkeys are auto-enabled for every user still on SMS or voice and a Microsoft-managed registration campaign starts nudging them; on 1 February 2027 Microsoft-provided SMS and voice telecom delivery is retired, and after that any user whose only MFA method is SMS or voice hits a blocking passkey-registration prompt with no opt-out. This playbook covers who is in scope, how to find your exposed users, how to move them to passkeys, when a customer-managed telecom provider is worth it, the temporary Graph opt-out and its limits, and how it all ties into your Conditional Access baseline. Dates and behaviours validated against Microsoft Learn, August 2026.

TheAdminStack Read →
Article Aug 1, 2026

Conditional Access Baseline Policies Every Microsoft 365 Tenant Needs in 2026

Every Microsoft 365 tenant should run a baseline of roughly eight to ten Conditional Access policies — block legacy authentication, require MFA for all users, phishing-resistant MFA for admins, compliant or managed devices, block device code flow, sign-in and user-risk policies, session controls, guest MFA, and a break-glass exclusion group — deployed in report-only first, piloted with a ring group, then enforced. This guide gives the named set, the safe rollout order, the P1/P2 licensing reality, the enforcement changes that landed in June and July 2026, and the production gotchas that lock teams out of their own tenant.

TheAdminStack Read →