Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
| Conditional Access policy | Scenario | License requirement |
| --- | --- | --- |
| [Block legacy authentication](/entra/fundamentals/configure-security#block-legacy-authentication) | All users | Microsoft Entra ID P1 |
| [Privileged Microsoft Entra built-in roles enforce phishing-resistant methods](/entra/fundamentals/configure-security#privileged-microsoft-entra-built-in-roles-are-targeted-with-conditional-access-policies-to-enforce-phishing-resistant-methods) | Privileged users | Microsoft Entra ID P1 |
| [All user sign-in activity uses strong authentication methods](/entra/fundamentals/configure-security#all-user-sign-in-activity-uses-strong-authentication-methods) | All users | Microsoft Entra ID P1 |
| [Guest access is protected by strong authentication methods](/entra/fundamentals/configure-security#guest-access-is-protected-by-strong-authentication-methods) | Guest access | Microsoft Entra ID P1 |
| [Secure the MFA registration (My Security Info) page](/entra/fundamentals/configure-security#secure-the-mfa-registration-my-security-info-page) | All users | Microsoft Entra ID P1 |
| [Require multifactor authentication for device join and device registration using user action](/entra/fundamentals/configure-security#require-multifactor-authentication-for-device-join-and-device-registration-using-user-action) | All users | Microsoft Entra ID P1 |
| [User sign-in activity uses token protection](/entra/fundamentals/configure-security#user-sign-in-activity-uses-token-protection) | All users | Microsoft Entra ID P1 |
| [Restrict device code flow](/entra/fundamentals/configure-security#restrict-device-code-flow) | All users | Microsoft Entra ID P1 |
| [Authentication transfer is blocked](/entra/fundamentals/configure-security#authentication-transfer-is-blocked) | All users | Microsoft Entra ID P1 |
| [Restrict access to high risk users](/entra/fundamentals/configure-security#restrict-access-to-high-risk-users) | All users | Microsoft Entra ID P2 |
| [Restrict high risk sign-ins](/entra/fundamentals/configure-security#restrict-high-risk-sign-ins) | All users | Microsoft Entra ID P2 |
| [Conditional Access policies for Privileged Access Workstations are configured](/entra/fundamentals/configure-security#conditional-access-policies-for-privileged-access-workstations-are-configured) | Privileged users | Microsoft Entra ID P1 |
#### Evaluate the policy impact
Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
Deploy policies in the following three phases to balance security improvements with minimal user disruption. Organizations can adjust timelines based on their size, complexity, and change management capabilities.
#### Phase 1: Foundation (Week 1-2)
Establish baseline security controls and prepare for MFA enforcement. **Prerequisites:** Ensure users can register for MFA before enabling enforcement policies.
| Order | Conditional Access policy | Scenario | License requirement |
| --- | --- | --- | --- |
| 1 | [Block legacy authentication](/entra/fundamentals/configure-security#block-legacy-authentication) | All users | Microsoft Entra ID P1 |
| 2 | [Secure the MFA registration (My Security Info) page](/entra/fundamentals/configure-security#secure-the-mfa-registration-my-security-info-page) | All users | Microsoft Entra ID P1 |
| 3 | [Privileged Microsoft Entra built-in roles enforce phishing-resistant methods](/entra/fundamentals/configure-security#privileged-microsoft-entra-built-in-roles-are-targeted-with-conditional-access-policies-to-enforce-phishing-resistant-methods) | Privileged users | Microsoft Entra ID P1 |
#### Phase 2: Core authentication (Week 2-3)
Enforce MFA for all users and guests. **Key impact:** Users will be required to use MFA for all sign-ins. Ensure communication plan is executed and support resources are available.
| Order | Conditional Access policy | Scenario | License requirement |