BSides Toronto 2023

Unconditionally Conditional - Strong Authentication in Microsoft Entra ID (formerly Azure AD)
10-21, 14:50–15:15 (US/Eastern), ENG 103

Conditional Access in Microsoft Entra ID, when tied with Mobile Application Management and Mobile Device Management in Microsoft Intune are the core pillars for building zero trust based access controls in Microsoft 365 and Azure published services. We will cover MDM and MAM policies, how device compliance is applied to Conditional Access by Intune when deploying authentication, and finishing off with a tested model for layered access, specifically as it relates to M365 in a variety of trust states.


Conditional Access in Microsoft Entra ID, when tied with Mobile Application Management and Mobile Device Management in Microsoft Intune are the core pillars for building zero trust based access controls in Microsoft 365 and Azure published services. We will cover MDM and MAM policies, how device compliance is applied to Conditional Access by Intune when deploying authentication, and finishing off with a tested model for layered access, specifically as it relates to M365 in a variety of trust states.

See also: Slides and resources

Don Mallory has over 30 years of experience in enterprise IT, primarily in critical infrastructure, specializing in operations, data storage, disaster recovery, and security for critical infrastructure. Professionally, Don is a Senior Security Analyst in the healthcare sector. He is also involved in various volunteer activities including C3X as a builder and mentor, co-organizer of Hak4Kidz Toronto and the Latow Photographer's Guild at the Art Gallery of Burlington, where he teaches traditional wet darkroom photography.