Identify the core features and objects of Microsoft 365 services
Microsoft Entra ID, Conditional Access, and SSO
Understand the identity plane, adaptive access decisions, authentication methods, and single sign-on.
What you need to know
- Microsoft Entra ID supplies cloud identity, authentication, application access, groups, and related governance capabilities.
- Conditional Access combines assignments and signals with grant, block, and session controls.
- MFA requires more than one factor; passwordless methods can improve phishing resistance depending on the method.
- SSO lets a user authenticate once and access integrated applications without repeated credential prompts.
Objects and administrative surfaces
- Users, groups, authentication methods, enterprise apps, sign-in logs, and Conditional Access — Microsoft Entra admin center.
- Conditional Access policies target users/workload identities, resources, conditions, and controls.
How it works
- Conditional Access evaluates after first-factor authentication and uses context such as user, device, location, application, and risk.
- All applicable Conditional Access policies must be satisfied; report-only mode records impact without enforcing most controls.
When to use it
- Require MFA or a compliant device with Conditional Access when access context demands it.
- Use SSO for a consistent integrated sign-in experience, not as a replacement for authorization.
Security and governance implications
- Exclude and monitor emergency-access accounts to reduce tenant lockout risk.
- Test policies with report-only mode and deploy in stages.
Troubleshooting signals
- Open the failed sign-in record and inspect status, authentication details, and Conditional Access evaluation.
- Confirm policy scope, exclusions, target resource, and grant controls.
Exam traps
- Conditional Access does not create users or assign licenses.
- SSO reduces repeated sign-ins but does not automatically grant every application permission.
Key takeaways
- Authentication proves identity; authorization grants access; Conditional Access evaluates context.
- Use sign-in logs to explain why a sign-in was blocked or challenged.
Related objectives
- D1.3.a
- D1.3.b
- D1.3.c
- D1.3.d
- D1.3.e