---
title: Conditional Access Policy Creation
description: This guide will provide a brief overview of creating a new conditional access policy that will be applied to an end user's authentication attempt into your Microsoft environment.
---

[Skip to content](https://knowledge.sittadel.com/conditional-access-policy-creation#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en)
3. [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)

# Conditional Access Policy Creation

## This guide will provide a brief overview of creating a new conditional access policy that will be applied to an end user's authentication attempt into your Microsoft environment.

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-04-16-2156-PM.png?width=125&height=133&name=image-png-Jan-19-2024-04-04-16-2156-PM.png)Role Requirements**

Procedure Scope: **Administrators**

Required Group Membership: **Admin.Security**

**![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-29-09-3760-PM.png?width=670&height=5&name=image-png-Jan-19-2024-04-29-09-3760-PM.png)**

**Creating a Conditional Access Policy**

1. Navigate to the [Conditional Access – Azure Active Directory](https://portal.azure.com/#view/Microsoft_AAD_ConditionalAccess/ConditionalAccessBlade/~/Policies) portal, locate and select **New Policy**.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-51-30-4930-PM.png?width=670&height=333&name=image-png-Sep-25-2024-01-51-30-4930-PM.png)
2. Provide a **Name** for the policy you wish to create, should hint at what the policy is trying to achieve.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-51-58-2915-PM.png?width=356&height=75&name=image-png-Sep-25-2024-01-51-58-2915-PM.png)
3. Make **Assignments** to the policy, start with the users or groups that it will apply to.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-52-21-4001-PM.png?width=609&height=265&name=image-png-Sep-25-2024-01-52-21-4001-PM.png)
4. Make sure to always add the organizational **Break Glass** account as an exclusion to any conditional access policy creation to prevent locking yourself out of your tenant.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-52-46-7940-PM.png?width=608&height=415&name=image-png-Sep-25-2024-01-52-46-7940-PM.png)
5. Next you can add **Application, Action, or Authentication-Based** parameter that must be met to gain access to the organizational tenant.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-53-15-6393-PM.png?width=610&height=315&name=image-png-Sep-25-2024-01-53-15-6393-PM.png)
6. The final piece of **Assignments** involves **Conditions** which will only apply to specific defined variables, such as location or a specific OS platform.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-53-47-8754-PM.png?width=603&height=370&name=image-png-Sep-25-2024-01-53-47-8754-PM.png)
7. After **Assignments** have been made you can now use **Access Control** to either **Block Access** if policy compliance isn’t achieved on a device or **Grant Access** which will provide allowance if one or more of the defined requirements is met.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-54-21-1384-PM.png?width=670&height=334&name=image-png-Sep-25-2024-01-54-21-1384-PM.png)
8. **Sessions** can be used to limit user access to cloud application, such as implementing a sign-in frequency to prevent users from being permanently logged into the organizational tenant.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-54-36-0487-PM.png?width=670&height=334&name=image-png-Sep-25-2024-01-54-36-0487-PM.png)
9. The last step is to select the deployment option for your newly created policy, if you don’t want the policy to affect the organizational environment right away leave it in **Report-Only** or **Off** until the appropriate accommodations can be made for deployment.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-54-51-2504-PM.png?width=325&height=160&name=image-png-Sep-25-2024-01-54-51-2504-PM.png)
10. If you implement any **Access Control** feature you will receive a prompt to prevent locking yourself out, we already included the **Break Glass** account for a user exclusion so select the **Proceed Anyway **option.  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-55-15-1013-PM.png?width=670&height=83&name=image-png-Sep-25-2024-01-55-15-1013-PM.png)
11. Once a policy is created, if will now be generated in the policies list and will include details such as name, status, and creation time.  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Sep-25-2024-01-55-26-9138-PM.png?width=646&height=40&name=image-png-Sep-25-2024-01-55-26-9138-PM.png)

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>