Authentication is essentially the process of validating a user is who they say they are, such that they can gain access to a system – in this context, the system is Share Point.

Authentication is not authorization, which is the process in determine if a known user is permitted access to certain data in the system, after successful authentication.

The risk based policies give an advanced baseline of coverage, challenging users for MFA or blocking access as risk is detected.

We’ve heard over and over again how critical it is for organizations to apply additional security to Exchange and Share Point, while not impacting access to other services.

Now, as part of the Conditional Access public preview, rules can be applied to Exchange or Share Point Online.

As a pre-requisite you’ll need an Office365 and Azure AD Premium license. At this point the Conditional Access policy we set above, and the user will need to complete MFA before getting access. Please give it a spin and let us know what you think. This is a set of capabilities that I know a LOT of you have been asking for. And as always, we would love to receive any feedback of suggestions you have.

A security measure designed to protect a communications system against acceptance of a fraudulent transmission or simulation by establishing the validity of a transmission, message, or originator. A means of identifying individuals and verifying their eligibility to receive specific categories of information.

This is a big step forward as we continue to build up the Conditional Access policy framework.

