Static Conditional Access checks are easy to bypass with residential proxies and stolen credentials. Risk-based policies evaluate session and identity posture continuously.

Preface

Traditional CA evaluates simple static conditions at sign-in. That is not enough when attackers spoof trusted networks or reuse leaked credentials.

Problem

Residential proxies can masquerade as local ISPs and bypass geo-based rules. Static policies may not demand stronger MFA or block unrecognized devices when risk is elevated.

Solution

Align with NIST SP 800-207 and Entra ID Protection:

  1. Sign-in risk policies: Require phishing-resistant MFA for medium/high risk sessions.
  2. User risk policies: Force secure password change on high user risk.
  3. Device compliance: Require Intune-compliant devices for corporate resource access.

PowerShell: Review Conditional Access Policies

Connect-MgGraph -Scopes "Policy.Read.All"
Get-MgIdentityConditionalAccessPolicy | Select-Object DisplayName, State, Conditions | Format-Table