CA-09Easy

How to Fix: Zero Trust Network Access

Step-by-step guide to implement zero trust network access in your Microsoft 365 environment.

5-10 minutes

Estimated Time

4

Steps

critical

Severity

Maximum Security

Baseline Level

Why This Matters

Full Zero Trust: never trust, always verify. Every access request is validated against device health, user risk, and location. This ensures compromised devices and credentials cannot access resources.

Prerequisites

  • 1Global Administrator or appropriate admin role in Microsoft Entra ID
  • 2Access to Microsoft Entra admin center (entra.microsoft.com)
  • 3Microsoft Entra ID P2 license
  • 4Conditional Access Administrator role (minimum)

Expected Configuration

  • All cloud app access requires a compliant device
  • Named locations are configured for corporate networks
  • Location-based blocking policies are enforced
  • Risk-based sign-in policies are active

Remediation Steps

1

Review Existing Policies

Examine your current Conditional Access policies.

  • Navigate to Microsoft Entra admin center
  • Go to Protection > Conditional Access
  • Review existing policies and their configurations
2

Design Policy Configuration

Plan the Conditional Access policy that addresses this control.

  • Define target users and groups
  • Determine target applications
  • Plan grant and session controls
3

Create or Update Policy

Implement the Conditional Access policy.

  • Create new policy or modify existing one
  • Configure assignments (users, apps, conditions)
  • Set appropriate grant and session controls
  • Start in Report-only mode for testing
4

Test and Enable

Validate the policy works correctly before full enforcement.

  • Monitor Report-only results
  • Test with pilot group
  • Switch to On when confident
  • Run TrueConfig scan to verify compliance

Auto-Remediation Available

TrueConfig can automatically fix this control for you. Enable auto-remediation to have this configuration applied and maintained automatically.

Learn about auto-remediation

Related Resources

Automate Your Security Configuration

TrueConfig continuously monitors your Microsoft 365 environment and can automatically fix configuration drift. Start your free trial today.

Start Free Trial