IntermediateCA-WS-001

Microsoft Entra Conditional Access Workshop

Design and operationalise zero-trust access policies with Microsoft Entra Conditional Access

A one-day intensive that takes identity administrators from Conditional Access fundamentals to a production-ready policy framework — covering risk-based access, session controls, breakglass design, and change management aligned to ASD Essential Eight and the ACSC Information Security Manual.

8 hours
New course
Certificate Included
Microsoft Entra Conditional Access Workshop

At a Glance

Who it's for

  • Identity and access administrators designing zero-trust policies
  • IT managers operationalising Conditional Access at scale
  • Microsoft 365 and Entra ID engineers tightening tenant security
  • Security architects aligning identity controls with ASD Essential Eight and the ACSC ISM

Course Details

Duration:8 hours
Format:One-day intensive workshop with hands-on labs
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Aligned to Microsoft Learn Conditional Access guidance and ACSC Information Security Manual identity controls

Course Overview

Microsoft Entra Conditional Access is the policy engine at the heart of a modern zero-trust architecture, evaluating signals from users, devices, locations, and applications to make real-time access decisions. This one-day intensive workshop equips identity administrators and IT managers to plan, deploy, and operate Conditional Access with confidence — moving beyond default templates to a tailored policy framework that meets Australian compliance expectations. You will work through Microsoft's recommended Conditional Access policy templates, layer in Identity Protection risk signals, configure session controls and app-enforced restrictions, and design the operational practices — report-only mode, breakglass accounts, and change management — that keep your policies safe to evolve. Every module is anchored to the Microsoft Learn Conditional Access planning guide and the ACSC Information Security Manual identity controls so the policies you build are defensible to auditors and resilient under incident.

What You'll Learn

Explain how Conditional Access evaluates signals and enforces grant and session controls
Deploy Microsoft's recommended baseline policies including blocking legacy authentication and requiring MFA for administrators
Configure device compliance and Intune integration as a Conditional Access grant control
Use Microsoft Entra ID Protection sign-in and user risk signals to drive risk-based Conditional Access
Apply session controls including sign-in frequency, persistent browser, and app-enforced restrictions
Design breakglass (emergency access) accounts excluded from Conditional Access in line with Microsoft guidance
Operate Conditional Access safely using report-only mode, What If, and structured change management
Map your Conditional Access posture to ASD Essential Eight MFA controls and ACSC ISM identity guidance

Course Curriculum

Module 1: Conditional Access Fundamentals

90 min
  • Conditional Access as the zero-trust policy engine
  • Assignments, conditions, and access controls explained
  • Licensing prerequisites (Entra ID P1, P2, and Microsoft 365 E5)
  • Policy evaluation order and combination logic
  • Mapping Conditional Access to the Microsoft Learn planning guide

Module 2: Common Conditional Access Patterns

120 min
  • Blocking legacy authentication protocols at the tenant edge
  • Requiring MFA for all users and for administrator roles
  • Device compliance as a grant control with Microsoft Intune
  • Location-based policies and trusted named locations
  • Implementing Microsoft's recommended policy templates

Module 3: Risk-Based Conditional Access with Identity Protection

90 min
  • Microsoft Entra ID Protection sign-in and user risk signals
  • Configuring risk-based Conditional Access policies
  • Self-service password reset and secure password change on user risk
  • Investigating risky users, sign-ins, and risk detections
  • Tuning risk policies to reduce false positives

Module 4: Session Controls and App-Enforced Restrictions

90 min
  • Sign-in frequency and persistent browser session controls
  • App-enforced restrictions for SharePoint Online and Exchange Online
  • Microsoft Defender for Cloud Apps conditional access app control
  • Continuous access evaluation (CAE) and token revocation
  • Protecting unmanaged devices with restricted web sessions

Module 5: Operationalising Conditional Access

90 min
  • Report-only mode and the What If tool for safe rollout
  • Designing breakglass (emergency access) accounts per Microsoft guidance
  • Change management, naming conventions, and policy documentation
  • Monitoring sign-in logs, audit logs, and Conditional Access insights workbook
  • Mapping policies to ASD Essential Eight MFA and ACSC ISM identity controls

Who Should Attend

  • Identity and access administrators
  • Microsoft 365 and Entra ID engineers
  • Security architects and cloud security leads
  • IT managers responsible for tenant security posture
  • Compliance and risk professionals overseeing identity controls

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • Working knowledge of Microsoft Entra ID users, groups, and authentication methods
  • • Familiarity with multi-factor authentication concepts
  • • Access to a Microsoft Entra ID P1 or P2 tenant for hands-on labs
  • • Understanding of zero-trust and least-privilege principles

Delivery, Format and Logistics

Delivery Mode

One-day intensive workshop with hands-on labs

Self-paced online with live Q&A sessions

What You'll Need

  • Microsoft Entra ID P1 or P2 tenant (trial acceptable) for hands-on labs
  • Global Reader or Conditional Access Administrator role in a non-production tenant
  • Working knowledge of Microsoft Entra ID users, groups, and multi-factor authentication
  • Familiarity with the principles of zero trust and least privilege

What You'll Receive

  • 8 hours of live and self-paced training
  • Conditional Access policy templates and naming standards
  • Breakglass account configuration checklist
  • Report-only rollout runbook
  • ASD Essential Eight and ACSC ISM mapping worksheet
  • Certificate of completion

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$599AUD
$799EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

One-day intensive workshop with hands-on labs

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 8 hours of live and self-paced training
  • Conditional Access policy templates and naming standards
  • Breakglass account configuration checklist
  • Report-only rollout runbook
  • ASD Essential Eight and ACSC ISM mapping worksheet
  • Certificate of completion

Have questions about this course?