Lab 10 – Conditional Access
MS-102: Microsoft 365 Administrator Essentials
Overview
Built and tested Conditional Access policies in Microsoft Entra ID, including a location-based block policy and an Intune device compliance-integrated access control scenario, using two Microsoft Learn interactive exercises.
Tasks Completed
- Created a Conditional Access policy scoped to a specific user and the My Apps cloud application
- Configured a location-based condition set to Any Location with a Grant control of Block Access
- Enabled the policy and confirmed that access to My Apps was blocked for the targeted account
- Disabled the policy after validation and confirmed access was restored
- Configured a second Conditional Access policy requiring Intune device compliance as a grant condition
- Tested the device compliance condition and reviewed expected access behavior on a Windows device
Source Material
Completed using Implement Conditional Access Policies, Roles and Assignments and Protect Data and Control Access with Intune and Conditional Access from Microsoft Learn. All steps were executed in a personal, paid Microsoft 365 test tenant.
← Back to MS-102 Labs