Static Conditional Access checks are easy to bypass with residential proxies and stolen credentials. Risk-based policies evaluate session and identity posture continuously.
Preface
Traditional CA evaluates simple static conditions at sign-in. That is not enough when attackers spoof trusted networks or reuse leaked credentials.
Problem
Residential proxies can masquerade as local ISPs and bypass geo-based rules. Static policies may not demand stronger MFA or block unrecognized devices when risk is elevated.
Solution
Align with NIST SP 800-207 and Entra ID Protection:
- Sign-in risk policies: Require phishing-resistant MFA for medium/high risk sessions.
- User risk policies: Force secure password change on high user risk.
- Device compliance: Require Intune-compliant devices for corporate resource access.
PowerShell: Review Conditional Access Policies
Connect-MgGraph -Scopes "Policy.Read.All"
Get-MgIdentityConditionalAccessPolicy | Select-Object DisplayName, State, Conditions | Format-Table