{"id":806,"date":"2026-10-06T20:31:19","date_gmt":"2026-10-06T19:31:19","guid":{"rendered":"https:\/\/www.mrpaulclarke.co.uk\/?page_id=806"},"modified":"2026-10-06T20:38:16","modified_gmt":"2026-10-06T19:38:16","slug":"case-study-securing-microsoft-365-with-conditional-access","status":"publish","type":"page","link":"https:\/\/www.mrpaulclarke.co.uk\/?page_id=806","title":{"rendered":"Case Study &#8211; Securing Microsoft 365 with Conditional Access"},"content":{"rendered":"<style>\n.ca-case {\n    max-width: 1100px;\n    margin: 0 auto;\n    font-family: inherit;\n    line-height: 1.7;\n    color: #263238;\n}<\/p>\n<p>.ca-case * {\n    box-sizing: border-box;\n}<\/p>\n<p>.ca-hero {\n    background: linear-gradient(135deg, #071c33 0%, #0b3b63 55%, #087ea4 100%);\n    color: #fff;\n    padding: 58px 45px;\n    border-radius: 18px;\n    margin-bottom: 32px;\n    position: relative;\n    overflow: hidden;\n}<\/p>\n<p>.ca-hero:after {\n    content: \"\";\n    position: absolute;\n    width: 280px;\n    height: 280px;\n    border-radius: 50%;\n    background: rgba(35,200,255,.12);\n    right: -70px;\n    top: -100px;\n}<\/p>\n<p>.ca-label {\n    display: inline-block;\n    background: rgba(255,255,255,.14);\n    color: #fff !important;\n    padding: 7px 14px;\n    border-radius: 30px;\n    font-size: .85rem;\n    font-weight: 700;\n    letter-spacing: .08em;\n    text-transform: uppercase;\n    margin-bottom: 18px;\n}<\/p>\n<p>.ca-hero h1 {\n    color: #fff !important;\n    font-size: 2.65rem;\n    line-height: 1.15;\n    margin: 0 0 18px;\n    max-width: 850px;\n}<\/p>\n<p>.ca-hero p {\n    color: #eaf8ff !important;\n    font-size: 1.15rem;\n    max-width: 820px;\n    margin: 0;\n}<\/p>\n<p>.ca-section {\n    margin: 40px 0;\n}<\/p>\n<p>.ca-section h2 {\n    color: #0b3b63;\n    font-size: 1.8rem;\n    margin-bottom: 15px;\n}<\/p>\n<p>.ca-section h3 {\n    color: #0b3b63;\n}<\/p>\n<p>.ca-grid {\n    display: grid;\n    grid-template-columns: repeat(2, 1fr);\n    gap: 20px;\n    margin: 25px 0;\n}<\/p>\n<p>.ca-card {\n    background: #fff;\n    border: 1px solid #e1e8ed;\n    border-radius: 14px;\n    padding: 25px;\n    box-shadow: 0 5px 18px rgba(0,0,0,.05);\n}<\/p>\n<p>.ca-card h3 {\n    margin-top: 0;\n    font-size: 1.2rem;\n}<\/p>\n<p>.ca-icon {\n    font-size: 2rem;\n    display: block;\n    margin-bottom: 12px;\n}<\/p>\n<p>.ca-highlight {\n    background: #eef8fc;\n    border-left: 5px solid #0b9fd3;\n    padding: 22px 25px;\n    border-radius: 8px;\n    margin: 28px 0;\n}<\/p>\n<p>.ca-warning {\n    background: #fff4f3;\n    border-left: 5px solid #d83a34;\n    padding: 22px 25px;\n    border-radius: 8px;\n    margin: 28px 0;\n}<\/p>\n<p>.ca-warning h3 {\n    color: #a5231e;\n    margin-top: 0;\n}<\/p>\n<p>.ca-success {\n    background: #effaf3;\n    border-left: 5px solid #28a35a;\n    padding: 22px 25px;\n    border-radius: 8px;\n    margin: 28px 0;\n}<\/p>\n<p>.ca-success h3 {\n    color: #19743d;\n    margin-top: 0;\n}<\/p>\n<p>.ca-steps {\n    counter-reset: ca-step;\n    margin: 28px 0;\n}<\/p>\n<p>.ca-step {\n    counter-increment: ca-step;\n    position: relative;\n    padding: 3px 0 28px 68px;\n    min-height: 58px;\n}<\/p>\n<p>.ca-step:before {\n    content: counter(ca-step);\n    position: absolute;\n    left: 0;\n    top: 0;\n    width: 46px;\n    height: 46px;\n    border-radius: 50%;\n    background: #0b79a8;\n    color: #fff;\n    font-weight: 700;\n    display: flex;\n    align-items: center;\n    justify-content: center;\n}<\/p>\n<p>.ca-step h3 {\n    margin: 0 0 5px;\n}<\/p>\n<p>.ca-results {\n    display: grid;\n    grid-template-columns: repeat(4, 1fr);\n    gap: 15px;\n    margin: 28px 0;\n}<\/p>\n<p>.ca-result {\n    background: #f6f9fb;\n    border-radius: 14px;\n    padding: 22px 18px;\n    text-align: center;\n}<\/p>\n<p>.ca-result span {\n    display: block;\n    font-size: 2rem;\n    margin-bottom: 8px;\n}<\/p>\n<p>.ca-result strong {\n    display: block;\n    color: #0b3b63;\n    margin-bottom: 5px;\n}<\/p>\n<p>.ca-quote {\n    font-size: 1.2rem;\n    font-weight: 600;\n    text-align: center;\n    color: #0b3b63;\n    padding: 32px;\n    margin: 38px 0;\n    background: #f6f9fb;\n    border-radius: 14px;\n}<\/p>\n<p>.ca-cta {\n    background: #071c33;\n    color: #fff !important;\n    padding: 40px;\n    border-radius: 16px;\n    margin-top: 42px;\n}<\/p>\n<p>.ca-cta h2,\n.ca-cta h3,\n.ca-cta strong,\n.ca-cta b,\n.ca-cta a {\n    color: #fff !important;\n}<\/p>\n<p>.ca-cta p {\n    color: #e6f1f7 !important;\n}<\/p>\n<p>.ca-case ul {\n    padding-left: 24px;\n}<\/p>\n<p>.ca-case li {\n    margin-bottom: 10px;\n}<\/p>\n<p>@media (max-width: 800px) {\n    .ca-results {\n        grid-template-columns: repeat(2, 1fr);\n    }\n}<\/p>\n<p>@media (max-width: 700px) {\n    .ca-grid,\n    .ca-results {\n        grid-template-columns: 1fr;\n    }<\/p>\n<p>    .ca-hero {\n        padding: 38px 25px;\n    }<\/p>\n<p>    .ca-hero h1 {\n        font-size: 2rem;\n    }\n}\n<\/style>\n<div class=\"ca-case\">\n<div class=\"ca-hero\">\n<span class=\"ca-label\">Microsoft 365 Security Case Study<\/span><\/p>\n<h1>Securing Microsoft 365 with Conditional Access<\/h1>\n<p>How suspicious account activity led to a Microsoft 365 security review, an upgrade to Business Premium and the introduction of Conditional Access to dramatically reduce the organisation&#8217;s exposure to account compromise.<\/p>\n<\/div>\n<div class=\"ca-section\">\n<h2>Overview<\/h2>\n<p>The incident began when a customer reported receiving suspicious emails that appeared to have originated from within their organisation.<\/p>\n<p>This immediately raised the possibility that a Microsoft 365 account may have been compromised.<\/p>\n<p>Rather than simply changing a password and considering the matter closed, the incident triggered a wider investigation into the organisation&#8217;s Microsoft 365 security posture.<\/p>\n<div class=\"ca-highlight\">\n<strong>The objective was not simply to deal with one suspicious account.<\/strong> It was to understand what had happened, contain any immediate risk and make it significantly harder for the same type of attack to succeed again.\n<\/div>\n<\/div>\n<div class=\"ca-section\">\n<h2>The Challenge<\/h2>\n<div class=\"ca-grid\">\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f3a3;<\/span><\/p>\n<h3>Suspicious Emails<\/h3>\n<p>Emails consistent with phishing or account compromise were being received, creating concern that credentials may have been exposed.<\/p>\n<\/div>\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f30d;<\/span><\/p>\n<h3>Overseas Sign-in Attempts<\/h3>\n<p>Microsoft Entra ID sign-in information showed authentication activity originating from multiple countries outside the organisation&#8217;s normal operating locations.<\/p>\n<\/div>\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f510;<\/span><\/p>\n<h3>Identity Security<\/h3>\n<p>The existing configuration relied heavily on usernames, passwords and the authentication controls already in place.<\/p>\n<\/div>\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f6e1;&#xfe0f;<\/span><\/p>\n<h3>Limited Access Controls<\/h3>\n<p>The existing Microsoft 365 licensing did not provide the full Conditional Access capabilities required for the security improvements we wanted to implement.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ca-section\">\n<h2>Immediate Response<\/h2>\n<p>When account compromise is suspected, the first priority is containment.<\/p>\n<p>Before making wider configuration changes, action was taken to secure the affected account and invalidate any access that an attacker may already have obtained.<\/p>\n<div class=\"ca-steps\">\n<div class=\"ca-step\">\n<h3>Password Reset<\/h3>\n<p>The user&#8217;s Microsoft 365 password was changed to prevent continued access using potentially compromised credentials.<\/p>\n<\/div>\n<div class=\"ca-step\">\n<h3>Multi-Factor Authentication Reviewed<\/h3>\n<p>The user&#8217;s authentication methods were reviewed and reset where appropriate to ensure an attacker had not registered or retained an authentication method.<\/p>\n<\/div>\n<div class=\"ca-step\">\n<h3>Active Sessions Revoked<\/h3>\n<p>Existing Microsoft 365 sessions were revoked so that previously issued authentication tokens could no longer simply continue accessing the account.<\/p>\n<\/div>\n<div class=\"ca-step\">\n<h3>Sign-in Activity Investigated<\/h3>\n<p>Microsoft Entra ID sign-in information was reviewed to identify unusual locations, authentication attempts and other suspicious activity.<\/p>\n<\/div>\n<\/div>\n<div class=\"ca-warning\">\n<h3>Why changing the password isn&#8217;t always enough<\/h3>\n<p>If an attacker already has an authenticated session, simply changing the user&#8217;s password may not immediately terminate every existing session. Revoking sessions and reviewing authentication methods are therefore important parts of responding to a suspected Microsoft 365 account compromise.<\/p>\n<\/div>\n<\/div>\n<div class=\"ca-section\">\n<h2>What the Investigation Found<\/h2>\n<p>The Microsoft Entra ID sign-in logs provided valuable visibility into authentication attempts against the tenant.<\/p>\n<p>Attempts were being made from geographical locations that were inconsistent with the customer&#8217;s normal business activity.<\/p>\n<p>While unsuccessful overseas authentication attempts do not automatically mean that an account has been compromised, they demonstrate an important reality of cloud services:<\/p>\n<div class=\"ca-quote\">\nA Microsoft 365 login page is available from virtually anywhere in the world \u2014 unless you put controls around who should be allowed to use it.\n<\/div>\n<p>This led to a wider discussion about reducing the organisation&#8217;s attack surface rather than simply reacting to suspicious login attempts after they occurred.<\/p>\n<\/div>\n<div class=\"ca-section\">\n<h2>The Licensing Gap<\/h2>\n<p>The customer was using Microsoft 365 Business Standard.<\/p>\n<p>Business Standard provides the core Microsoft 365 productivity services, but the additional identity, device management and security capabilities included with <strong>Microsoft 365 Business Premium<\/strong> made it a much better fit for the security controls required.<\/p>\n<div class=\"ca-highlight\">\nThe decision was therefore made to upgrade the users from <strong>Microsoft 365 Business Standard to Microsoft 365 Business Premium<\/strong>.\n<\/div>\n<p>This wasn&#8217;t simply an Office licensing upgrade. Business Premium opened the door to a much broader set of security and management capabilities, including Microsoft Entra ID Conditional Access and Microsoft Intune.<\/p>\n<\/div>\n<div class=\"ca-section\">\n<h2>The Solution: Conditional Access<\/h2>\n<p>Conditional Access allows Microsoft Entra ID to evaluate the circumstances surrounding a sign-in before deciding whether access should be granted.<\/p>\n<p>Instead of relying solely on the question:<\/p>\n<div class=\"ca-highlight\">\n<strong>&#8220;Does this person know the correct password?&#8221;<\/strong>\n<\/div>\n<p>Microsoft 365 can consider additional information such as:<\/p>\n<ul>\n<li>who the user is<\/li>\n<li>where the sign-in originates<\/li>\n<li>which application is being accessed<\/li>\n<li>whether multi-factor authentication has been completed<\/li>\n<li>the type of device being used<\/li>\n<li>whether the device is managed or compliant<\/li>\n<li>the level of risk associated with the sign-in<\/li>\n<\/ul>\n<p>This allows access decisions to be based on context rather than simply possession of a username and password.<\/p>\n<\/div>\n<div class=\"ca-section\">\n<h2>Using Named Locations<\/h2>\n<p>The organisation&#8217;s users normally operated from the United Kingdom, so geographical information could be used as an additional security control.<\/p>\n<p>Named Locations were configured within Microsoft Entra ID and incorporated into the Conditional Access design.<\/p>\n<p>This allowed sign-ins originating from unexpected geographical regions to be restricted rather than simply allowing authentication attempts from anywhere in the world.<\/p>\n<div class=\"ca-success\">\n<h3>Reducing the attack surface<\/h3>\n<p>If an organisation has no legitimate requirement for users to sign in from certain parts of the world, restricting those locations can remove a significant amount of unnecessary exposure.<\/p>\n<\/div>\n<div class=\"ca-warning\">\n<h3>Location controls are not a silver bullet<\/h3>\n<p>Geographical restrictions should form part of a layered security strategy. Attackers can use VPNs, proxies or compromised infrastructure within an allowed country, so location should never replace strong authentication, device controls and sensible monitoring.<\/p>\n<\/div>\n<\/div>\n<div class=\"ca-section\">\n<h2>Strengthening Multi-Factor Authentication<\/h2>\n<p>Conditional Access was also used to strengthen the way multi-factor authentication was applied.<\/p>\n<p>MFA provides an important additional layer of protection because possession of a password alone should not be enough to access company information.<\/p>\n<p>However, MFA is most effective when combined with sensible access policies and modern authentication methods.<\/p>\n<div class=\"ca-grid\">\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f511;<\/span><\/p>\n<h3>Password<\/h3>\n<p>The user&#8217;s password remains one component of authentication, but it should never be treated as the organisation&#8217;s only defence.<\/p>\n<\/div>\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f4f1;<\/span><\/p>\n<h3>MFA<\/h3>\n<p>Additional authentication helps prevent stolen credentials alone from providing immediate access to Microsoft 365.<\/p>\n<\/div>\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f4cd;<\/span><\/p>\n<h3>Location<\/h3>\n<p>Conditional Access can identify whether the authentication request originates from an expected or permitted location.<\/p>\n<\/div>\n<div class=\"ca-card\">\n<span class=\"ca-icon\">&#x1f4bb;<\/span><\/p>\n<h3>Device<\/h3>\n<p>Business Premium also provides the foundations for controlling access according to whether a device is managed and compliant.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ca-section\">\n<h2>A Layered Approach to Microsoft 365 Security<\/h2>\n<p>The project demonstrated why modern Microsoft 365 security shouldn&#8217;t depend upon one individual control.<\/p>\n<p>No single technology makes an organisation immune to phishing or account compromise.<\/p>\n<p>Instead, several controls work together:<\/p>\n<ul>\n<li>strong passwords<\/li>\n<li>multi-factor authentication<\/li>\n<li>Conditional Access<\/li>\n<li>Named Locations<\/li>\n<li>session revocation during security incidents<\/li>\n<li>authentication method reviews<\/li>\n<li>Microsoft Entra ID sign-in monitoring<\/li>\n<li>managed and compliant devices<\/li>\n<li>endpoint protection<\/li>\n<li>user awareness<\/li>\n<\/ul>\n<p>If one layer fails, another can still prevent or limit the attack.<\/p>\n<\/div>\n<div class=\"ca-section\">\n<h2>The Results<\/h2>\n<div class=\"ca-results\">\n<div class=\"ca-result\">\n<span>&#x1f6e1;&#xfe0f;<\/span><br \/>\n<strong>Stronger Security<\/strong><br \/>\nMicrosoft 365 access was protected by additional identity-based controls.\n<\/div>\n<div class=\"ca-result\">\n<span>&#x1f30d;<\/span><br \/>\n<strong>Reduced Exposure<\/strong><br \/>\nUnnecessary authentication from unexpected geographical locations could be restricted.\n<\/div>\n<div class=\"ca-result\">\n<span>&#x1f510;<\/span><br \/>\n<strong>Improved Authentication<\/strong><br \/>\nMFA became part of a wider Conditional Access strategy rather than a standalone control.\n<\/div>\n<div class=\"ca-result\">\n<span>&#x1f4bb;<\/span><br \/>\n<strong>Future Ready<\/strong><br \/>\nBusiness Premium provided additional options for Intune, device compliance and endpoint security.\n<\/div>\n<\/div>\n<p>The immediate security incident was contained, but more importantly, the organisation emerged with a considerably stronger Microsoft 365 security posture.<\/p>\n<p>Rather than waiting for the next suspicious login and reacting to it, controls were introduced to make many unwanted authentication attempts far less likely to succeed in the first place.<\/p>\n<\/div>\n<div class=\"ca-section\">\n<h2>Going Further with Business Premium<\/h2>\n<p>Conditional Access was one of the most important improvements, but Microsoft 365 Business Premium provides considerably more security capability than geographical restrictions alone.<\/p>\n<p>Further controls can include:<\/p>\n<ul>\n<li>Microsoft Intune device management<\/li>\n<li>device compliance policies<\/li>\n<li>requiring compliant devices for sensitive services<\/li>\n<li>Microsoft Defender for Business<\/li>\n<li>Windows security baselines<\/li>\n<li>BitLocker management<\/li>\n<li>stronger authentication methods<\/li>\n<li>application protection policies<\/li>\n<li>controlled administrator access<\/li>\n<\/ul>\n<div class=\"ca-highlight\">\nMoving to Business Premium created a platform on which the organisation&#8217;s security could continue to mature rather than solving only the immediate problem.\n<\/div>\n<\/div>\n<div class=\"ca-cta\">\n<h2>From Incident Response to Better Security<\/h2>\n<p>What began as an investigation into suspicious emails ultimately became an opportunity to strengthen the customer&#8217;s entire Microsoft 365 security posture.<\/p>\n<p>By reviewing the sign-in evidence, securing the affected account, upgrading to Microsoft 365 Business Premium and implementing Conditional Access, the organisation gained much greater control over how and where its cloud services could be accessed.<\/p>\n<p><strong>Good security isn&#8217;t just about responding to an attack. It&#8217;s about making the next attack considerably harder.<\/strong><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft 365 Security Case Study Securing Microsoft 365 with Conditional Access How suspicious account activity led to a Microsoft 365 security review, an upgrade to Business Premium and the introduction of Conditional Access to dramatically reduce the organisation&#8217;s exposure to account compromise. Overview The incident began when a customer reported receiving suspicious emails that appeared&hellip; <br \/> <a class=\"read-more\" href=\"https:\/\/www.mrpaulclarke.co.uk\/?page_id=806\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":809,"parent":683,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-806","page","type-page","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/806","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=806"}],"version-history":[{"count":3,"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/806\/revisions"}],"predecessor-version":[{"id":808,"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/806\/revisions\/808"}],"up":[{"embeddable":true,"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/683"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=\/wp\/v2\/media\/809"}],"wp:attachment":[{"href":"https:\/\/www.mrpaulclarke.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=806"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}