Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

6.2. Quick Reference

Decision tables compressing Phases 2–5. If a row surprises you, revisit its section.

License Tier Map

FeatureFreeP1P2Governance add-on
MFA via security defaults
Conditional Access
Dynamic groups, group-based licensing
SSPR with writeback, Connect Health, custom roles
ID Protection (risk policies), PIM, access reviews
Entitlement mgmt (full), lifecycle workflowspartial
Workload identity CA / riskWorkload ID Premium

"Which feature?" Discriminators

Requirement phraseAnswerNot
Phishing-resistant MFAPasskeys/FIDO2, WHfB, CBA via authentication strengthAuthenticator push, SMS
Bootstrap passwordless / lost methodTemporary Access PassPassword reset
Step-up for a sensitive resource/actionAuthentication context (+ protected actions for directory ops)New app-wide policy
Dry-run a CA policyReport-only mode + What IfPilot group enforcement
Sign-in risk remediationRequire MFA (risk-based CA)Password change
User risk remediationSecure password change (needs writeback if hybrid)MFA alone
VPN replacement, any TCP/UDP, workforceGSA Private Access (client + connectors)App Proxy
Publish one on-prem web app, no client, partnersApplication Proxy (Entra pre-auth)Private Access
Corporate-network-only without IP listsCompliant network check (GSA)Named locations
Block sign-ins to foreign tenantsTenant restrictions v2 (M365 profile)Cross-tenant access settings
Delegate admin over one departmentAdministrative unit + scoped roleCustom role alone
Protect VIPs from broad helpdesk rolesRestricted management AURegular AU
Partner MFA honored, no double-promptCross-tenant access trust settingsCA exclusion
Auto-provision users between owned tenantsCross-tenant synchronizationBulk invite
Immediate on-prem password policy at cloud sign-inPTAPHS
Sign-in survives on-prem outagePHSPTA, AD FS
Sync a disconnected forest, light footprint, HACloud SyncConnect Sync
Azure workload calls Azure/Graph, no secretsManaged identity (user-assigned if shared/persistent)Service principal + secret
External CI/CD calls Azure, no stored secretsWorkload identity federationClient secret in vault
Daemon reads all mailboxesApplication permission + client credentials + admin consentDelegated permission
Users request blocked-consent apps with approvalAdmin consent workflowDisable consent only
Unmanaged devices: browser-only, no downloadsCA session control → MDCA session policy (or app-enforced restrictions for SPO/EXO)Block access
Requestable, expiring, approved access bundlesAccess package (entitlement mgmt)Direct group adds
Auto-delete guests when access endsEntitlement mgmt external user lifecycleManual review
Recertify access periodically, auto-removeAccess reviews (auto-apply ON)Entitlement mgmt
Just-in-time admin, approval, time-boundPIM eligible + role settingsStanding assignment
One activation grants several rolesPIM for Groups + role-assignable groupMultiple activations
Retain logs years / query logs / feed SplunkStorage account / Log Analytics / Event HubPortal retention
Posture recommendations and trendIdentity Secure ScoreSign-in logs

Break-Glass Card

Two cloud-only accounts · permanent active Global Administrator (never eligible) · excluded from all CA policies · phishing-resistant credentials stored offline · sign-in alerting via Log Analytics alert rule · tested quarterly.

Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications