---
title: "Conditional Access — Identity Glossary | IDSync"
description: "Conditional Access is an IdP policy capability that evaluates signals (user, device, location, app, risk score) at authentication time and decides whether…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Conditional Access",
          "item": "https://idsync.com/glossary/conditional-access"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/conditional-access",
      "name": "Conditional Access",
      "alternateName": [
        "Conditional Access",
        "Adaptive Access",
        "Risk-Based Authentication"
      ],
      "description": "Conditional Access is an IdP policy capability that evaluates signals (user, device, location, app, risk score) at authentication time and decides whether to allow, block, require MFA, require a compliant device, or require step-up authentication.",
      "url": "https://idsync.com/glossary/conditional-access",
      "inDefinedTermSet": "https://idsync.com/glossary"
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  Conditional Access 

Authentication

# Conditional Access

Conditional Access is an IdP policy capability that evaluates signals (user, device, location, app, risk score) at authentication time and decides whether to allow, block, require MFA, require a compliant device, or require step-up authentication.

Last reviewed 3 months ago

Key points

-   Originated as Microsoft Conditional Access in Entra ID; Okta calls it 'Adaptive Authentication,' Google calls it 'Context-Aware Access.'
-   Signals: user/group, sign-in risk, user risk, device compliance, location/IP, application, client type.
-   Outcomes: allow, block, require MFA, require compliant device, require password change, session restrictions.
-   Foundation of Zero Trust workforce identity — replaces 'on the corporate network' as the implicit trust signal.
-   Effectiveness depends on signal quality (device posture telemetry, threat intelligence, behavioral analytics).

## What is Conditional Access?

**Conditional Access** is the policy layer in a modern IdP that decides — at the moment of authentication or session establishment — whether to allow, deny, or step up a request based on **context**. Instead of "if password+MFA succeeds, allow," conditional access asks:

-   _Who is the user?_ (group membership, employment status)
-   _What's the user's risk score?_ (impossible travel, leaked credentials, anomalous behavior)
-   _What device are they on?_ (managed, compliant, jailbroken, unknown)
-   _Where are they?_ (country, IP reputation, named location)
-   _What app are they trying to reach?_ (high-risk, regulated, public)
-   _How are they connecting?_ (browser, legacy auth, modern auth, native app)

…and then enforces an outcome: allow, block, require phishing-resistant MFA, require a managed compliant device, force a password reset, or restrict the session (no download, no clipboard).

## When buyers care

-   **Zero Trust adoption** — conditional access is how the "never trust, always verify" principle becomes policy.
-   **Compliance** — SOC 2, ISO 27001, NYDFS, HIPAA all benefit from documented adaptive access rules.
-   **Insider risk and account takeover** — risky-sign-in and risky-user signals catch what static MFA misses.
-   **BYOD / contractor access** — block unmanaged devices from sensitive apps without a full MDM rollout.

## Common policies worth implementing

1.  **Require phishing-resistant MFA for admin roles** — non-negotiable.
2.  **Block legacy authentication protocols** — basic auth, IMAP/POP/SMTP on Microsoft 365.
3.  **Require compliant device for finance / source code / customer data apps.**
4.  **Block sign-ins from countries you don't operate in** (with break-glass exceptions).
5.  **Force step-up for high-risk sign-ins** — risk score above threshold, new device, new location.

## Common mistakes

-   **No break-glass account** — locking yourself out of your own IdP because every admin needs a managed device that no longer exists.
-   **Policy sprawl** — too many overlapping policies make outcomes unpredictable. Use a small set of well-named policies.
-   **Trusting "trusted networks" too much** — VPN IPs and corporate egress aren't trust signals anymore.

## Editorial note

Conditional access is genuinely the highest-ROI security feature in modern IdPs. If you have Entra ID P1/P2 or an Okta plan with adaptive auth, the policies above pay for themselves.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[iam platforms](/directory/category/iam-platforms)[zero trust](/directory/category/zero-trust)

### Related terms

[zero trust](/glossary/zero-trust)[multi factor authentication](/glossary/multi-factor-authentication)[phishing resistant mfa](/glossary/phishing-resistant-mfa)[itdr](/glossary/itdr)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the iam platforms category.

[Explore tools](/directory/category/iam-platforms)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.