
Before you evaluate the next security tool, look at the licence you already pay for. In many Microsoft 365 environments we review, one of the most effective protection features sits idle there: Conditional Access. Not half configured, not configured at all.
This is not a niche problem. Account takeovers today run through the sign-in, not through the firewall. And Conditional Access sits exactly at the sign-in: a layer of rules that decides for every login whether it gets through, needs a second confirmation or gets blocked.
The uncomfortable punchline: for many SMEs, the next security gain is not a purchase. It is a configuration in a product that has long been on the invoice.
If-then rules for every sign-in
Conditional Access is quickly explained, and that is part of its strength. It is a set of if-then rules for logins: when someone signs in, check who it is, from where, with which device and to which application. Then decide.
A few decisions you can express with it:
- Sign-ins over outdated protocols that cannot support multifactor authentication are blocked outright.
- Anyone accessing company data from an unknown device needs a second confirmation.
- Administrator accounts need it every time.
- Access to particularly sensitive applications is only possible from managed devices.
This is not rocket science. It is the kind of control a doorman exercises: he looks at who is arriving and decides based on the situation. The difference from the doorman is that the rules apply to every single sign-in, around the clock, without getting tired.
Take the case that can hit any SME. A password shows up in a data leak, somewhere, at some point, without anyone noticing. Months later someone tries it out, at night, from an IP address no employee has ever signed in from. Without sign-in rules, the password alone decides in that moment. With a single rule, a second confirmation also decides, one the attacker cannot provide. Same attack, different ending, and the difference was a configuration.
Why this matters shows in the attacks that actually happen. Most account takeovers start with a password that leaked somewhere or a phishing email that worked. Microsoft states in its own documentation that more than 99.9 percent of common identity-related attacks are stopped by multifactor authentication and blocking legacy authentication protocols (source: Microsoft Learn). Translated plainly: the two most effective measures against the most common form of attack are configuration decisions, not products. How the sign-in layer fits into a phishing defence is something we described in our post on phishing prevention in your business.
You have probably already paid for Conditional Access
Now for the part that interests us as cost optimisers.
Conditional Access requires a Microsoft Entra ID P1 licence. That licence is part of Microsoft 365 Business Premium, and according to Microsoft's licensing documentation, Business Premium customers can use the feature directly. Business Premium is exactly the licence many Swiss SMEs have had in place for years, often without ever touching the security part.
That creates a strange situation. A company pays month after month for a licence that contains a ready-made protection layer. At the same time it sits in sales meetings for additional security products, some of which are supposed to address exactly this gap. The vendor rarely mentions that the foundation is already paid for. Why would he, he earns on the new sale.
In our reviews the same picture keeps repeating: Business Premium licensed for all employees, a separately paid tool next to it that is supposed to do part of the same job, and not a single active sign-in rule in the tenant itself. The problem at these companies is rarely too little budget. It is paid protection that was never switched on. We described the principle in more detail in our post on consolidating security tools. The short version: before a new tool enters the budget, the question of what the existing licences already cover belongs on the table.
Some context for smaller environments: if you only have the free Entra ID tier, Microsoft gives you the so-called security defaults, a fixed baseline with multifactor authentication and blocked legacy protocols. That is a good start and better than nothing, and Microsoft now switches this baseline on by itself for new tenants. That says a lot about how seriously the vendor itself takes the sign-in layer. Conditional Access is the level above: the same protection idea, but with your own rules instead of a one-size package. Exceptions, stricter rules for individual groups, a special case for the production floor without smartphones: all of that you can only model with Conditional Access.
There is, by the way, a second place where this topic will find you whether you want it to or not: the cyber insurance application. The questionnaires we fill in with clients ask about multifactor authentication almost without exception, often explicitly for external access and administrator accounts. Ticking no here means paying more or getting no cover at all. Ticking yes when it is not true means a bigger problem than the premium once a claim comes. This question too is answered in the end by your sign-in configuration, not by your shelf of tools.
Why it stays switched off anyway
If the feature is paid for and effective, why is it so often not running?
The answer has nothing to do with technology. Conditional Access is not an installation problem but a series of decisions: who may access what, from where, and under which conditions? No product can answer these questions. It takes someone who knows the business, knows the exceptions and has the nerve to switch a rule live.
An example of such a decision: should employees be able to sign in from abroad? The reflex answer is "of course, we have people travelling". The useful answer is more precise: who actually travels on business, where to, and needs more than mail and Teams while doing so? In many SMEs the list is short. Then the rest of the world can be restricted for the rest of the company without anyone noticing it in daily work. Decisions like these are written in no handbook because they depend on your business. Which is exactly why they stay undone.
And this is where things jam in SMEs, in two places.
First: nobody is responsible. The IT provider operates what was ordered. Nobody ever ordered the sign-in rules, so they do not exist. That is not a failure of the provider but a gap in the mandate. How you organise security tasks like this without your own security team leads straight to the question of ownership, which we take on for our clients in security management: define what should apply, and make sure someone operates it.
Second: the fear of locking yourself out. It is justified, a badly built rule can cut half the company off from their mailboxes on a Monday morning. But this risk has been addressed for years. Conditional Access has a report-only mode: the rule runs alongside, logs for every sign-in what it would have decided, and enforces none of it. You see in black and white who a rule would affect before it affects anyone. Add an emergency account outside all rules, and the two classic objections are defused.
What remains is the uncomfortable rest: someone has to make the decisions and maintain the state. Rules age, exceptions pile up, new applications arrive, and the exception for that one supplier from 2024 needs to come out again at some point. That is operations work, unspectacular and permanent. Exactly the kind of work that appears in no sales brochure and is therefore chronically underestimated. We saw the same pattern with M365 Copilot: the risk did not sit in the product. It sat in the permissions around it that nobody had cleaned up.
Look at your own licence first
If you do only one thing after this text: ask your IT lead or provider which Conditional Access rules are active in your Microsoft 365 tenant. The answer is revealing whichever way it goes. "None" is a clear work order. "These ones" is a good occasion to check whether the rules still match how you work today. Hesitation before the answer tells you the most.
If you want to judge the answer, three checkpoints are enough for a start. Does your tenant require a second confirmation from everyone, at least outside their familiar environment? Are the outdated sign-in protocols blocked, the ones that cannot do a second confirmation at all? And do stricter rules apply to administrator accounts than to everyone else? Three times yes is a solid base to build on. Anything below that means: you are paying for protection you are not getting.
None of this is expensive. The licence is already running, report-only mode removes the lockout risk, and the first baseline rules are manageable. What it takes is an owner and a few deliberate decisions. That is less than most security projects cost, and it achieves more than some of them.
If you are not sure where your tenant stands, or do not want to make these decisions alone, we are happy to look at it together. An initial conversation is non-binding, and afterwards you will know whether you have a gap or only an unanswered question.
And there is one question we take away from every one of these conversations: how many of the sign-ins that get through at your company today would you still allow tomorrow if you could see them all?




