ms.author: joflore
author: MicrosoftGuyJFlo
ms.date: 06/06/2025
ms.service: entra-id
ms.subservice: conditional-access
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
In preview, the Security Copilot agent evaluates policies requiring multifactor authentication (MFA), enforces device based controls (device compliance, app protection policies, and Domain Joined Devices), and blocks legacy authentication and device code flow.
The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies.
- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
- On average, each agent run consumes less than one SCU.
- To activate the agent the first time, you need the [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../role-based-access-control/permissions-reference.md#global-administrator) role during the preview.
- To interact with the agent and apply suggestions, you need the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role.
- For more information, see [Understand authentication in Microsoft Security Copilot](/copilot/security/authentication)
- Device-based controls require [Microsoft Intune licenses](/intune/intune-service/fundamentals/licenses).
ms.author: joflore
author: MicrosoftGuyJFlo
ms.date: 06/09/2025
ms.service: entra-id
ms.subservice: conditional-access
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
In preview, the Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow.
The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies.
- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
- On average, each agent run consumes less than one SCU.
- To activate the agent the first time, you need the [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../role-based-access-control/permissions-reference.md#global-administrator) role during the preview.
- You can assign [Conditional Access Administrators](../role-based-access-control/permissions-reference.md#conditional-access-administrator) with Security Copilot access, which gives your Conditional Access Administrators the ability to use the agent as well.
- For more information, see [Assign Security Copilot access](/copilot/security/authentication#assign-security-copilot-access)
- Device-based controls require [Microsoft Intune licenses](/intune/intune-service/fundamentals/licenses).