Conditional Access
Last updated:
ENTRAAZURE
How
- Once authentication is done, Entra ID creates Refresh Token and Access Token.
- It sends RT and AT to user
- User sends AT to App
- ATs are time-bombed
- After time is done, new RT and AT generated
- If a new app requires authentication, user can use the same AT
- Every ask for token goes through [[202404011557 Conditional Access|conditional access]]
Overview
- Allows you to set conditions for access
- device
- location
- apps
- Access controls (make multiple selections)
- use MFA, FIDO2, etc.
- password policy etc
- Session controls
- continuous access evaluation
- cap