Conditional Access

In short
Conditional access means rules that decide at every sign-in whether access is granted, based on person, device, location, application and risk. Instead of «signed in or not» it becomes «signed in, on a managed device, from a plausible country». Access turns into a decision made per situation rather than a permanent state.
What it actually shuts down
The most common real incident in business is a password someone handed over. After that the attacker signs in normally – to the system it is a valid login.
That is exactly where the rule bites: a sign-in from an unknown device in a country the company does not operate in gets refused or has to be confirmed separately. The password is right, the circumstances are not.
The mistake that gets expensive
Locking yourself out. A rule that applies to all accounts also applies to the account you would use to change it. Set a condition your own device does not meet and you cannot get back in.
Every rollout therefore needs a break-glass account excluded from the rules and secured separately – plus a trial run where the rule only reports before it enforces.
For a Swiss company
The capability belongs to Microsoft 365 identity management and is not included in every plan; which tier is required belongs checked before planning. It is the most common surprise on this topic.
On substance, the simplest rule is worth having first: access to company data only from managed devices. It is anchored in Microsoft Intune and excludes the private laptop nobody can vouch for.
How we handle it
We introduce rules in stages, starting in report-only mode, and with a break-glass account in place before the first rule enforces.
Embedded in IT security, Microsoft 365 and the zero trust approach it puts into practice.
A term in your quote that nobody explained?
In a strategy call we translate the offer in front of you – even when it did not come from us.