Create a broad Conditional Access strategy from the protections your tenant needs.
Create a focused policy pack for one group, resource, partner, or exception.
Paste or drop an export to compare current Conditional Access policies with the rebuild set.
Upload an Entra ID sign-in log export to quantify Conditional Access gaps and build a matching strategy.
Step 1 of 4
What needs protecting?
Choose only the areas that apply to your environment. CA Architect will consolidate compatible controls into the fewest safe policies.
Step 2 of 4
Your consolidated architecture
Threat coverage
MITRE techniques addressed and remaining gaps
View coverage
Threat coverage
MITRE techniques addressed and remaining gaps
Why some controls stay separate Guardrails for policies that should not be merged.
Baseline traceability Shows which original baseline policies are represented by each consolidated policy.
MITRE detail and residual gaps Extra ATT&CK mapping and items Conditional Access cannot solve alone.
Advanced threat model Optional scope, suggested threats, and control mapping for engineers who want to tune the strategy manually.
Choose an identity and target to see suggested threats and matching controls.
Scope
Identity and target
Identity profile
Target resources
Threat model
Threats to defend against
Step 1 of 4
Choose the closest access pattern
Start with the situation that best matches the access need. You can tune the important details in the next step.
Step 2 of 4
Describe the access requirements
These answers shape the policy. Tenant object IDs are requested only when you prepare the final export.
Visual policy designer
Build the access decision from left to right
Choose who is signing in and what they need. The recommended controls adapt as you move through the path.
Live policy blueprint
Minimum safe policy set
The map branches only when combining controls would change Conditional Access behaviour.
Scenario outcome
Secure access plan
Threats mitigated
MITRE coverage and remaining gaps
View coverage
Threats mitigated
MITRE coverage and remaining gaps
Recommended policy pack
Build these scenario policies
Prerequisites
Before Conditional Access
Manual build notes
What to configure
Step 4 of 4
Add the tenant objects required for export
The policy design is ready. Supply only the object IDs required by this scenario, then open the build guide or apply the policy pack.
Policy detail
Select a policy
Select a policy to review controls, structured edits, and Graph JSON.
Rollout decision
Recommended states start higher-risk controls in report-only where supported.
Prerequisites
Required objects
Manual build guide
Interactive Entra build path
Exact portal actions generated from the configured export shapeStructured edits
Export overrides
Sanitized Graph JSON
v1.0 policy shapeImport and compare
Your current tenant export
Comparison target: full baseline library.
Log analysis
Entra sign-in log gap analysis
Everything stays in your browser. Entra's JSON download gives you four files — select all of them at once and they merge into one report.