Microsoft renamed Azure AD to Entra ID in 2023, but the star feature is older: conditional access, the policy engine deciding who gets in, from what device, from where.
It's the single biggest lever against account takeover we deploy. The catch: policy design is unforgiving, one careless rule locks out the CEO at the airport. Test in report-only mode first; we learned that one properly.
Verdict: the control we'd keep if we could keep only one.
Reviewed from live fleet experience · published June 2026 · we earn a fair margin on some products we supply; reviews are not sponsored.
