{"id":57695,"date":"2026-06-28T09:25:35","date_gmt":"2026-06-27T23:25:35","guid":{"rendered":"https:\/\/www.cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/"},"modified":"2026-06-28T09:27:00","modified_gmt":"2026-06-27T23:27:00","slug":"conditional-access-gaps-that-put-business-accounts-at-risk-today","status":"publish","type":"post","link":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/","title":{"rendered":"Conditional Access Gaps That Put Business Accounts at Risk Today"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In this blog post Conditional Access Gaps That Put Business Accounts at Risk Today we will look at the common access control mistakes that quietly expose business accounts, even when Microsoft 365 appears to be protected.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p class=\"wp-block-paragraph\">Most account breaches do not start with a dramatic hack. They start with a stolen password, a tired employee approving a sign-in prompt, or an old app that still accepts basic username and password access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is where Conditional Access comes in. Conditional Access is a Microsoft Entra ID feature, formerly part of Azure Active Directory, that decides who can access your business systems, from where, on what device, and under what conditions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Think of it as a smart security gate for Microsoft 365, Azure, and connected business apps. Instead of asking only \u201cis the password correct?\u201d, it asks better questions: Is this the right person? Are they using a trusted device? Are they signing in from a normal location? Is the request risky? Should we ask for multi-factor authentication, block access, or allow them in?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Conditional Access matters to business leaders<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your organisation uses Microsoft 365, your user accounts are now one of your most valuable business assets. Email, Teams, SharePoint, OneDrive, finance systems, customer files, project data, and admin portals are often connected to the same identity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That means one compromised account can create a lot of damage. Attackers can read email, impersonate executives, redirect payments, access files, reset passwords, or quietly wait for the right invoice to change.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Australian organisations, this also has compliance implications. The Essential 8, the Australian government\u2019s cybersecurity framework that many organisations are now required or expected to follow, places strong emphasis on multi-factor authentication and restricting administrative privileges. Conditional Access is one of the practical ways Microsoft environments can support those controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But there is a catch. Conditional Access is powerful, but it is not automatically safe just because it is switched on. Poorly designed policies can leave large gaps that business leaders never see until something goes wrong.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Gap 1 Your policies do not cover every user<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most common issues we see is selective protection. The IT team creates a policy for full-time staff, but external users, shared mailboxes, contractors, service accounts, or older admin accounts are missed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From a business point of view, attackers do not care whether an account belongs to an employee, a contractor, or an old project mailbox. If it can sign in and access data, it is useful to them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A safer approach is to start with broad coverage and only exclude accounts where there is a clear, documented reason. Even emergency \u201cbreak glass\u201d accounts, which are special accounts kept for disaster recovery, should be tightly controlled, monitored, and reviewed regularly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business outcome:<\/strong> fewer hidden entry points, less chance of a forgotten account becoming the way into your business.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Gap 2 Multi-factor authentication is enabled, but not well controlled<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many businesses believe they are safe because multi-factor authentication, or MFA, is turned on. MFA means users need more than a password to sign in, usually a phone prompt, app code, security key, or biometric check.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The problem is that not all MFA methods provide the same level of protection. SMS codes can be intercepted. Basic push notifications can be approved by mistake. Users who receive repeated prompts may eventually tap \u201capprove\u201d just to make the interruption stop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For everyday users, this may be manageable with the right settings and training. For finance teams, executives, and administrators, stronger controls are usually needed. This may include number matching in the Microsoft Authenticator app, device compliance checks, or phishing-resistant methods such as security keys or passkeys.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In plain English, the goal is simple: do not just ask for another factor. Make sure the second factor actually proves the right person is signing in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business outcome:<\/strong> reduced risk of account takeover, invoice fraud, and executive impersonation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Gap 3 Legacy authentication is still allowed<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Legacy authentication is an older way for apps and services to connect using only a username and password. It does not properly support modern security checks like MFA and Conditional Access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This often exists because of old mail clients, scanners, printers, reporting tools, or line-of-business systems. The system may still work, so nobody questions it. Unfortunately, attackers love these older paths because they can bypass many of the controls businesses believe are protecting them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Blocking legacy authentication is one of the highest-value security improvements a Microsoft 365 organisation can make. Before doing it, you should check what still relies on it, plan replacements, and avoid breaking business-critical processes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At CloudProInc, we often treat this as a clean-up exercise rather than a switch-flip. The question is not \u201ccan we block it today?\u201d The better question is \u201cwhat old dependency is stopping us from blocking it safely?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business outcome:<\/strong> fewer easy attack paths, cleaner systems, and less reliance on outdated tools.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Gap 4 Device trust is missing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A password and MFA prompt tell you something about the user. They do not tell you whether the laptop or phone is safe.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is where Microsoft Intune becomes important. Intune manages and secures company devices, including laptops, phones, and tablets. It can help confirm whether a device has encryption enabled, a screen lock, current security updates, and approved security settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conditional Access can then use that information. For example, your business could allow access to sensitive finance data only from a managed and compliant device, while still allowing less sensitive access from other approved scenarios.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without device checks, a user may access company data from a personal laptop with no encryption, an outdated browser, shared family use, or unknown malware. The user may be legitimate, but the device may not be safe.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business outcome:<\/strong> lower chance of data leakage from unmanaged devices and better control over remote work.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Gap 5 Location rules are too trusting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many organisations allow easier access from \u201ctrusted locations\u201d, usually office IP addresses. This can be useful, but it can also create a false sense of safety.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Office networks change. Staff work from home. VPNs route traffic in unexpected ways. Attackers can use cloud infrastructure, proxies, or compromised devices to appear less suspicious than they really are.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Location should be one signal, not the whole decision. A sign-in from Australia may still be risky if the device is unknown, the user behaviour is unusual, or the account has administrator rights.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Melbourne-based and Australian businesses with interstate teams, overseas contractors, or international clients, location policies need careful design. Blocking every overseas sign-in might sound safe, but it can disrupt legitimate work. Allowing everything is worse.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business outcome:<\/strong> better protection without blocking staff who genuinely need to work across locations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Gap 6 Administrator access is treated like normal user access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Administrator accounts are different. They can change security settings, create users, reset passwords, access data, and sometimes control billing or cloud infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an attacker compromises an administrator account, the damage can escalate quickly. This is why admin access should be protected with stricter Conditional Access policies than standard user accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Good practice includes requiring strong MFA, blocking access from unmanaged devices, limiting admin access to approved locations or secure workstations, and separating everyday accounts from admin accounts. In simple terms, the account someone uses to read email should not be the same account they use to change tenant-wide security settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This also supports Essential 8 expectations around restricting administrative privileges. It is not just a technical preference; it is a governance and risk control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business outcome:<\/strong> reduced blast radius if a user account is compromised and stronger control over high-risk actions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Gap 7 Policies are created once and then forgotten<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Conditional Access is not a set-and-forget tool. Your business changes, staff roles change, apps are added, licences change, and attackers change their methods.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We often see environments with old test policies, duplicated rules, undocumented exclusions, and report-only policies that were never reviewed. Report-only mode lets administrators test a policy before enforcing it, which is useful, but it should not become a permanent parking bay.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A sensible review checks which policies exist, who they apply to, what they exclude, whether they overlap, and whether sign-in logs show unexpected behaviour. This does not need to be complicated, but it does need to be regular.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business outcome:<\/strong> fewer surprises, cleaner governance, and better confidence that controls are actually working.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A real-world scenario<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Consider a 180-person professional services firm using Microsoft 365 across Melbourne, Sydney, and a few remote staff overseas. The leadership team believed MFA was in place, and technically it was.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During a Conditional Access review, several issues appeared. Contractors were excluded from the main policy. One legacy mail protocol was still active for an old application. Admin accounts could sign in from unmanaged devices. A trusted location rule was allowing easier access than intended.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of these issues looked dramatic on their own. Together, they created a practical path for an attacker: target a less protected account, bypass stronger controls through an old protocol, then look for ways to escalate access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fix was not a massive rebuild. It was a structured clean-up: remove unnecessary exclusions, block legacy authentication after confirming business impact, separate admin accounts, introduce stronger MFA for privileged users, connect device compliance through Intune, and set a quarterly review process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result was a much stronger security posture without making daily work harder for most staff. That is the balance good Conditional Access should aim for.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Practical steps to reduce your Conditional Access risk<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n <li><strong>Map every policy.<\/strong> List what exists, who it applies to, which apps it covers, and what is excluded.<\/li>\n <li><strong>Check MFA coverage.<\/strong> Confirm that all users, administrators, guests, and high-risk roles are protected appropriately.<\/li>\n <li><strong>Block legacy authentication.<\/strong> Identify old dependencies first, then remove or replace them safely.<\/li>\n <li><strong>Use device compliance.<\/strong> Connect Conditional Access with Microsoft Intune, which manages and secures company devices.<\/li>\n <li><strong>Protect administrator accounts separately.<\/strong> Admin access should have stronger rules than normal user access.<\/li>\n <li><strong>Review exclusions.<\/strong> Every exclusion should have an owner, reason, approval, and expiry or review date.<\/li>\n <li><strong>Monitor sign-ins.<\/strong> Look for unusual locations, repeated failures, risky sign-ins, and unexpected access patterns.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Where CloudProInc can help<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Conditional Access sits at the intersection of Microsoft 365, identity, device management, compliance, and cybersecurity. That is why it is easy to configure something that looks right on the surface but leaves gaps underneath.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CloudProInc is a Melbourne-based Microsoft Partner and Wiz Security Integrator with more than 20 years of enterprise IT experience. We work across Azure, Microsoft 365, Microsoft Intune, Windows 365, Microsoft Defender, Wiz, OpenAI, and Claude, helping organisations design practical controls that support the way people actually work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our focus is not to make your environment unnecessarily complex. It is to reduce risk, support compliance, and make sure your security settings match your business reality.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final thought<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Conditional Access can be one of the most valuable security controls in your Microsoft environment. But if it has gaps, exclusions, weak MFA, unmanaged devices, or forgotten legacy access, it can also create a dangerous false sense of confidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are not sure whether your current Conditional Access setup is protecting your business properly, CloudProInc is happy to take a look. No pressure, no scare tactics \u2014 just a practical review of where the risks are and what can be improved.<\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Conditional Access can stop account attacks before they become breaches, but only if it is designed, tested, and maintained properly.<\/p>\n","protected":false},"author":1,"featured_media":57697,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_opengraph-title":"Business Accounts at Risk: Conditional Access Gaps","_yoast_wpseo_opengraph-description":"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.","_yoast_wpseo_twitter-title":"Business Accounts at Risk: Conditional Access Gaps","_yoast_wpseo_twitter-description":"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.","_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[13],"tags":[],"class_list":["post-57695","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Business Accounts at Risk: Conditional Access Gaps<\/title>\n<meta name=\"description\" content=\"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Business Accounts at Risk: Conditional Access Gaps\" \/>\n<meta property=\"og:description\" content=\"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/\" \/>\n<meta property=\"og:site_name\" content=\"CPI Consulting\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-27T23:25:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-27T23:27:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cloudproinc.azurewebsites.net\/wp-content\/uploads\/2026\/06\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"CPI Staff\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Business Accounts at Risk: Conditional Access Gaps\" \/>\n<meta name=\"twitter:description\" content=\"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"CPI Staff\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/\"},\"author\":{\"name\":\"CPI Staff\",\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#\\\/schema\\\/person\\\/192eeeb0ce91062126ce3822ae88fe6e\"},\"headline\":\"Conditional Access Gaps That Put Business Accounts at Risk Today\",\"datePublished\":\"2026-06-27T23:25:35+00:00\",\"dateModified\":\"2026-06-27T23:27:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/\"},\"wordCount\":1873,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png\",\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/\",\"url\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/\",\"name\":\"Business Accounts at Risk: Conditional Access Gaps\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png\",\"datePublished\":\"2026-06-27T23:25:35+00:00\",\"dateModified\":\"2026-06-27T23:27:00+00:00\",\"description\":\"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#primaryimage\",\"url\":\"\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png\",\"contentUrl\":\"\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png\",\"width\":1536,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cloudproinc.com.au\\\/index.php\\\/2026\\\/06\\\/28\\\/conditional-access-gaps-that-put-business-accounts-at-risk-today\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Conditional Access Gaps That Put Business Accounts at Risk Today\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#website\",\"url\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/\",\"name\":\"Cloud Pro Inc - CPI Consulting Pty Ltd\",\"description\":\"Cloud, AI &amp; Cybersecurity Consulting | Melbourne\",\"publisher\":{\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#organization\",\"name\":\"Cloud Pro Inc - Cloud Pro Inc - CPI Consulting Pty Ltd\",\"url\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/favfinalfile.png\",\"contentUrl\":\"\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/favfinalfile.png\",\"width\":500,\"height\":500,\"caption\":\"Cloud Pro Inc - Cloud Pro Inc - CPI Consulting Pty Ltd\"},\"image\":{\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/#\\\/schema\\\/person\\\/192eeeb0ce91062126ce3822ae88fe6e\",\"name\":\"CPI Staff\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d96eeb53b791d92c8c50dd667e3beec92c93253bb6ff21c02cfa8ca73665c70?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d96eeb53b791d92c8c50dd667e3beec92c93253bb6ff21c02cfa8ca73665c70?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d96eeb53b791d92c8c50dd667e3beec92c93253bb6ff21c02cfa8ca73665c70?s=96&d=mm&r=g\",\"caption\":\"CPI Staff\"},\"sameAs\":[\"http:\\\/\\\/www.cloudproinc.com.au\"],\"url\":\"https:\\\/\\\/cloudproinc.azurewebsites.net\\\/index.php\\\/author\\\/cpiadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Business Accounts at Risk: Conditional Access Gaps","description":"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/","og_locale":"en_US","og_type":"article","og_title":"Business Accounts at Risk: Conditional Access Gaps","og_description":"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.","og_url":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/","og_site_name":"CPI Consulting","article_published_time":"2026-06-27T23:25:35+00:00","article_modified_time":"2026-06-27T23:27:00+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/cloudproinc.azurewebsites.net\/wp-content\/uploads\/2026\/06\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png","type":"image\/png"}],"author":"CPI Staff","twitter_card":"summary_large_image","twitter_title":"Business Accounts at Risk: Conditional Access Gaps","twitter_description":"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.","twitter_misc":{"Written by":"CPI Staff","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#article","isPartOf":{"@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/"},"author":{"name":"CPI Staff","@id":"https:\/\/cloudproinc.azurewebsites.net\/#\/schema\/person\/192eeeb0ce91062126ce3822ae88fe6e"},"headline":"Conditional Access Gaps That Put Business Accounts at Risk Today","datePublished":"2026-06-27T23:25:35+00:00","dateModified":"2026-06-27T23:27:00+00:00","mainEntityOfPage":{"@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/"},"wordCount":1873,"commentCount":0,"publisher":{"@id":"https:\/\/cloudproinc.azurewebsites.net\/#organization"},"image":{"@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#primaryimage"},"thumbnailUrl":"\/wp-content\/uploads\/2026\/06\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png","articleSection":["Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/","url":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/","name":"Business Accounts at Risk: Conditional Access Gaps","isPartOf":{"@id":"https:\/\/cloudproinc.azurewebsites.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#primaryimage"},"image":{"@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#primaryimage"},"thumbnailUrl":"\/wp-content\/uploads\/2026\/06\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png","datePublished":"2026-06-27T23:25:35+00:00","dateModified":"2026-06-27T23:27:00+00:00","description":"See how access control gaps expose business accounts to stolen passwords, weak MFA, legacy sign-ins, and unmanaged devices before attackers can get in.","breadcrumb":{"@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#primaryimage","url":"\/wp-content\/uploads\/2026\/06\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png","contentUrl":"\/wp-content\/uploads\/2026\/06\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png","width":1536,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/cloudproinc.com.au\/index.php\/2026\/06\/28\/conditional-access-gaps-that-put-business-accounts-at-risk-today\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cloudproinc.azurewebsites.net\/"},{"@type":"ListItem","position":2,"name":"Conditional Access Gaps That Put Business Accounts at Risk Today"}]},{"@type":"WebSite","@id":"https:\/\/cloudproinc.azurewebsites.net\/#website","url":"https:\/\/cloudproinc.azurewebsites.net\/","name":"Cloud Pro Inc - CPI Consulting Pty Ltd","description":"Cloud, AI &amp; Cybersecurity Consulting | Melbourne","publisher":{"@id":"https:\/\/cloudproinc.azurewebsites.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cloudproinc.azurewebsites.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cloudproinc.azurewebsites.net\/#organization","name":"Cloud Pro Inc - Cloud Pro Inc - CPI Consulting Pty Ltd","url":"https:\/\/cloudproinc.azurewebsites.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cloudproinc.azurewebsites.net\/#\/schema\/logo\/image\/","url":"\/wp-content\/uploads\/2022\/01\/favfinalfile.png","contentUrl":"\/wp-content\/uploads\/2022\/01\/favfinalfile.png","width":500,"height":500,"caption":"Cloud Pro Inc - Cloud Pro Inc - CPI Consulting Pty Ltd"},"image":{"@id":"https:\/\/cloudproinc.azurewebsites.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/cloudproinc.azurewebsites.net\/#\/schema\/person\/192eeeb0ce91062126ce3822ae88fe6e","name":"CPI Staff","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/2d96eeb53b791d92c8c50dd667e3beec92c93253bb6ff21c02cfa8ca73665c70?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2d96eeb53b791d92c8c50dd667e3beec92c93253bb6ff21c02cfa8ca73665c70?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d96eeb53b791d92c8c50dd667e3beec92c93253bb6ff21c02cfa8ca73665c70?s=96&d=mm&r=g","caption":"CPI Staff"},"sameAs":["http:\/\/www.cloudproinc.com.au"],"url":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/author\/cpiadmin\/"}]}},"jetpack_featured_media_url":"\/wp-content\/uploads\/2026\/06\/conditional-access-gaps-that-put-business-accounts-at-risk-today.png","jetpack-related-posts":[{"id":57683,"url":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/2026\/06\/24\/conditional-access-checklist-for-microsoft-365-tenants-in-2026\/","url_meta":{"origin":57695,"position":0},"title":"Conditional Access Checklist for Microsoft 365 Tenants in 2026","author":"CPI Staff","date":"June 24, 2026","format":false,"excerpt":"A practical checklist for securing Microsoft 365 access without frustrating staff, reducing account takeover risk, and supporting Essential 8 alignment.","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"\/wp-content\/uploads\/2026\/06\/conditional-access-checklist-for-microsoft-365-tenants-in-2026.png","width":350,"height":200,"srcset":"\/wp-content\/uploads\/2026\/06\/conditional-access-checklist-for-microsoft-365-tenants-in-2026.png 1x, \/wp-content\/uploads\/2026\/06\/conditional-access-checklist-for-microsoft-365-tenants-in-2026.png 1.5x, \/wp-content\/uploads\/2026\/06\/conditional-access-checklist-for-microsoft-365-tenants-in-2026.png 2x, \/wp-content\/uploads\/2026\/06\/conditional-access-checklist-for-microsoft-365-tenants-in-2026.png 3x, \/wp-content\/uploads\/2026\/06\/conditional-access-checklist-for-microsoft-365-tenants-in-2026.png 4x"},"classes":[]},{"id":57511,"url":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/2026\/04\/30\/the-microsoft-365-tenant-looked-fine-until-we-checked-the-security-defaults\/","url_meta":{"origin":57695,"position":1},"title":"The Microsoft 365 Tenant Looked Fine Until We Checked the Security Defaults","author":"CPI Staff","date":"April 30, 2026","format":false,"excerpt":"Every Microsoft 365 tenant tells a story. Emails flowing, Teams meetings running, SharePoint humming along. From the outside, everything looks operational. But operational is not the same as secure \u2014 and the gap between those two things is where breaches happen. When our team conducts a Microsoft 365 security assessment,\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"\/wp-content\/uploads\/2026\/04\/the-microsoft-365-tenant-looked-fine-until-we-checked-the-security-defaults-cover.png","width":350,"height":200,"srcset":"\/wp-content\/uploads\/2026\/04\/the-microsoft-365-tenant-looked-fine-until-we-checked-the-security-defaults-cover.png 1x, \/wp-content\/uploads\/2026\/04\/the-microsoft-365-tenant-looked-fine-until-we-checked-the-security-defaults-cover.png 1.5x, \/wp-content\/uploads\/2026\/04\/the-microsoft-365-tenant-looked-fine-until-we-checked-the-security-defaults-cover.png 2x, \/wp-content\/uploads\/2026\/04\/the-microsoft-365-tenant-looked-fine-until-we-checked-the-security-defaults-cover.png 3x, \/wp-content\/uploads\/2026\/04\/the-microsoft-365-tenant-looked-fine-until-we-checked-the-security-defaults-cover.png 4x"},"classes":[]},{"id":57542,"url":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/2026\/05\/09\/how-conditional-access-and-intune-work-together-to-protect-your-business\/","url_meta":{"origin":57695,"position":2},"title":"How Conditional Access and Intune Work Together to Protect Your Business","author":"CPI Staff","date":"May 9, 2026","format":false,"excerpt":"Too many Microsoft 365 security projects stall at the same point. Multi-factor authentication is on, devices are enrolled, and policies exist in a few different admin portals, but leadership still cannot answer a simple question: can an unmanaged or unhealthy device reach company data? That gap is where Conditional Access\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"\/wp-content\/uploads\/2026\/05\/how-conditional-access-and-intune-protect-your-business-cover.png","width":350,"height":200,"srcset":"\/wp-content\/uploads\/2026\/05\/how-conditional-access-and-intune-protect-your-business-cover.png 1x, \/wp-content\/uploads\/2026\/05\/how-conditional-access-and-intune-protect-your-business-cover.png 1.5x, \/wp-content\/uploads\/2026\/05\/how-conditional-access-and-intune-protect-your-business-cover.png 2x, \/wp-content\/uploads\/2026\/05\/how-conditional-access-and-intune-protect-your-business-cover.png 3x, \/wp-content\/uploads\/2026\/05\/how-conditional-access-and-intune-protect-your-business-cover.png 4x"},"classes":[]},{"id":56890,"url":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/2026\/01\/23\/implement-zero-trust-with-entra-id-and-intune\/","url_meta":{"origin":57695,"position":3},"title":"Implement Zero Trust With Entra ID and Intune","author":"CPI Staff","date":"January 23, 2026","format":false,"excerpt":"Learn how to implement Zero Trust using Microsoft Entra ID and Intune with practical steps, key policies, and rollout tips. Secure access and devices without slowing users down.","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"\/wp-content\/uploads\/2026\/01\/post-5.png","width":350,"height":200,"srcset":"\/wp-content\/uploads\/2026\/01\/post-5.png 1x, \/wp-content\/uploads\/2026\/01\/post-5.png 1.5x, \/wp-content\/uploads\/2026\/01\/post-5.png 2x, \/wp-content\/uploads\/2026\/01\/post-5.png 3x, \/wp-content\/uploads\/2026\/01\/post-5.png 4x"},"classes":[]},{"id":57508,"url":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/2026\/04\/30\/the-hidden-risk-of-unmanaged-devices-accessing-microsoft-365\/","url_meta":{"origin":57695,"position":4},"title":"The Hidden Risk of Unmanaged Devices Accessing Microsoft 365","author":"CPI Staff","date":"April 30, 2026","format":false,"excerpt":"Most Australian organisations have invested in Microsoft 365 licences, security policies, and compliance controls. But there is a gap that regularly gets overlooked \u2014 and attackers know exactly where it is. Unmanaged devices. A personal laptop, a contractor's home PC, or a smartphone that was never enrolled in Intune. Each\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"\/wp-content\/uploads\/2026\/04\/the-hidden-risk-of-unmanaged-devices-accessing-microsoft-365-cover.png","width":350,"height":200,"srcset":"\/wp-content\/uploads\/2026\/04\/the-hidden-risk-of-unmanaged-devices-accessing-microsoft-365-cover.png 1x, \/wp-content\/uploads\/2026\/04\/the-hidden-risk-of-unmanaged-devices-accessing-microsoft-365-cover.png 1.5x, \/wp-content\/uploads\/2026\/04\/the-hidden-risk-of-unmanaged-devices-accessing-microsoft-365-cover.png 2x, \/wp-content\/uploads\/2026\/04\/the-hidden-risk-of-unmanaged-devices-accessing-microsoft-365-cover.png 3x, \/wp-content\/uploads\/2026\/04\/the-hidden-risk-of-unmanaged-devices-accessing-microsoft-365-cover.png 4x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/posts\/57695","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/comments?post=57695"}],"version-history":[{"count":1,"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/posts\/57695\/revisions"}],"predecessor-version":[{"id":57696,"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/posts\/57695\/revisions\/57696"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/media\/57697"}],"wp:attachment":[{"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/media?parent=57695"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/categories?post=57695"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudproinc.azurewebsites.net\/index.php\/wp-json\/wp\/v2\/tags?post=57695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}