Microsoft Entra Conditional Access Workshop
Design and operationalise zero-trust access policies with Microsoft Entra Conditional Access
A one-day intensive that takes identity administrators from Conditional Access fundamentals to a production-ready policy framework — covering risk-based access, session controls, breakglass design, and change management aligned to ASD Essential Eight and the ACSC Information Security Manual.

At a Glance
Who it's for
- Identity and access administrators designing zero-trust policies
- IT managers operationalising Conditional Access at scale
- Microsoft 365 and Entra ID engineers tightening tenant security
- Security architects aligning identity controls with ASD Essential Eight and the ACSC ISM
Course Details
Course Overview
Microsoft Entra Conditional Access is the policy engine at the heart of a modern zero-trust architecture, evaluating signals from users, devices, locations, and applications to make real-time access decisions. This one-day intensive workshop equips identity administrators and IT managers to plan, deploy, and operate Conditional Access with confidence — moving beyond default templates to a tailored policy framework that meets Australian compliance expectations. You will work through Microsoft's recommended Conditional Access policy templates, layer in Identity Protection risk signals, configure session controls and app-enforced restrictions, and design the operational practices — report-only mode, breakglass accounts, and change management — that keep your policies safe to evolve. Every module is anchored to the Microsoft Learn Conditional Access planning guide and the ACSC Information Security Manual identity controls so the policies you build are defensible to auditors and resilient under incident.
What You'll Learn
Course Curriculum
Module 1: Conditional Access Fundamentals
90 min- Conditional Access as the zero-trust policy engine
- Assignments, conditions, and access controls explained
- Licensing prerequisites (Entra ID P1, P2, and Microsoft 365 E5)
- Policy evaluation order and combination logic
- Mapping Conditional Access to the Microsoft Learn planning guide
Module 2: Common Conditional Access Patterns
120 min- Blocking legacy authentication protocols at the tenant edge
- Requiring MFA for all users and for administrator roles
- Device compliance as a grant control with Microsoft Intune
- Location-based policies and trusted named locations
- Implementing Microsoft's recommended policy templates
Module 3: Risk-Based Conditional Access with Identity Protection
90 min- Microsoft Entra ID Protection sign-in and user risk signals
- Configuring risk-based Conditional Access policies
- Self-service password reset and secure password change on user risk
- Investigating risky users, sign-ins, and risk detections
- Tuning risk policies to reduce false positives
Module 4: Session Controls and App-Enforced Restrictions
90 min- Sign-in frequency and persistent browser session controls
- App-enforced restrictions for SharePoint Online and Exchange Online
- Microsoft Defender for Cloud Apps conditional access app control
- Continuous access evaluation (CAE) and token revocation
- Protecting unmanaged devices with restricted web sessions
Module 5: Operationalising Conditional Access
90 min- Report-only mode and the What If tool for safe rollout
- Designing breakglass (emergency access) accounts per Microsoft guidance
- Change management, naming conventions, and policy documentation
- Monitoring sign-in logs, audit logs, and Conditional Access insights workbook
- Mapping policies to ASD Essential Eight MFA and ACSC ISM identity controls
Who Should Attend
- Identity and access administrators
- Microsoft 365 and Entra ID engineers
- Security architects and cloud security leads
- IT managers responsible for tenant security posture
- Compliance and risk professionals overseeing identity controls
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Working knowledge of Microsoft Entra ID users, groups, and authentication methods
- • Familiarity with multi-factor authentication concepts
- • Access to a Microsoft Entra ID P1 or P2 tenant for hands-on labs
- • Understanding of zero-trust and least-privilege principles
Delivery, Format and Logistics
Delivery Mode
One-day intensive workshop with hands-on labs
Self-paced online with live Q&A sessions
What You'll Need
- Microsoft Entra ID P1 or P2 tenant (trial acceptable) for hands-on labs
- Global Reader or Conditional Access Administrator role in a non-production tenant
- Working knowledge of Microsoft Entra ID users, groups, and multi-factor authentication
- Familiarity with the principles of zero trust and least privilege
What You'll Receive
- 8 hours of live and self-paced training
- Conditional Access policy templates and naming standards
- Breakglass account configuration checklist
- Report-only rollout runbook
- ASD Essential Eight and ACSC ISM mapping worksheet
- Certificate of completion
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
One-day intensive workshop with hands-on labs
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 8 hours of live and self-paced training
- Conditional Access policy templates and naming standards
- Breakglass account configuration checklist
- Report-only rollout runbook
- ASD Essential Eight and ACSC ISM mapping worksheet
- Certificate of completion
Have questions about this course?