Article
Aug 1, 2026
Conditional Access Baseline Policies Every Microsoft 365 Tenant Needs in 2026
Every Microsoft 365 tenant should run a baseline of roughly eight to ten Conditional Access policies — block legacy authentication, require MFA for all users, phishing-resistant MFA for admins, compliant or managed devices, block device code flow, sign-in and user-risk policies, session controls, guest MFA, and a break-glass exclusion group — deployed in report-only first, piloted with a ring group, then enforced. This guide gives the named set, the safe rollout order, the P1/P2 licensing reality, the enforcement changes that landed in June and July 2026, and the production gotchas that lock teams out of their own tenant.