August 30, 2019 By Adam Case 3 min read

Implementing conditional access procedures is a crucial part of a zero-trust strategy. But its fair to ask yourself, isn’t access always conditional? Isn’t access to systems and data always granted on the condition that, at a minimum, users enter a username and password? True enough. But the term “conditional access” refers to a specific approach to managing network security. Let’s talk about what it means and why it’s important.

Driven by the shift to mobile and cloud, conditional access is a process that enables IT security teams to validate or verify devices and users using a set of automated policies to protect networks and data. Policies may pertain to a specific use context or any number of factors, such as the user profile, the nature of the device, time of day, geographical location and what data the user is attempting to access. For that reason, the term “informed access” is catching on to describe the next level of authorization in which a system is informed that a given user is real, compliant and trusted.

The outcome of each access attempt can be dynamically determined, and individual sessions can even be monitored and controlled in real time, based on the risk assessment and access policies in effect. Conditional or informed access provides a scalable way to address various scenarios in which a user or a device may be suspect. For example, let’s say a user accesses the network from a particular city. Then, an hour later, the same user — or what appears to be the same user — attempts to access the network from a city in a different part of the world. An effective access policy could require the second attempt to be blocked.

For a more typical example, a legitimate user may attempt to access the network using a device with an out-of-date operating system. An access solution would be able to detect the out-of-date system and access would be withheld. The user would be notified that the situation must be remedied before access is granted, and the solution could offer instructions to bring the device into compliance. Such a self-service process has the added benefit of reducing calls to the help desk and eliminating the need for IT intervention.

How to Configure Conditional Access Policies

Access policies can apply a combination of rules based on defined conditions. Predefined access policies can be created by a software provider, or an IT team can create its own policies based on the organization’s specific needs.

An access policy for mobile devices might require devices to be enrolled (managed) in the company’s mobility management tool. A mobile device could be:

  1. Managed and in full compliance with the organization’s IT policies;
  2. Managed, but with an out-of-date operating system or out of compliance for some other reason; or
  3. Not managed in the company’s mobility management tool.

Each of these three device conditions would be treated differently depending on the status of the device and the sensitivity of the system or data the user is attempting to access.

There are many possible access policies and configurations, but the following examples paint a simple picture of how these policies can be applied. The particular policy chosen would be based on the network or data the user wants to access:

  • Less sensitive data — Users with managed devices — compliant or noncompliant — are allowed access. But users with unmanaged devices must complete additional two-factor authentication (2FA) to gain access.
  • Moderately sensitive data — Users with managed, compliant devices are allowed access. Users with devices that are managed but noncompliant must complete 2FA. Users with unmanaged devices are blocked.
  • Very sensitive data — Users with managed, compliant devices are allowed access with additional 2FA. Users with managed, noncompliant devices and users with unmanaged devices are both blocked.

Convenience for the World of Cloud and Mobile

In today’s business environment, mobility and convenience are essential, both for customers and employees. Even when they’re outside the corporate perimeter, employees accessing work-related systems and information expect the same level of speed and convenience they enjoy when conducting transactions on their favorite online shopping sites.

Conditional, informed access solutions provide a systematic way to provide that quick, convenient and secure access with a minimum of IT involvement and maximum speed and simplicity for the user.

More from Data Protection

Data security tools make data loss prevention more efficient

3 min read - As businesses navigate the complexities of modern-day cybersecurity initiatives, data loss prevention (DLP) software is the frontline defense against potential data breaches and exfiltration. DLP solutions allow organizations to detect, react to and prevent data leakage or misuse of sensitive information that can lead to catastrophic consequences. However, while DLP solutions play a critical role in cybersecurity, their effectiveness significantly improves when integrated with the right tools and infrastructure. Key limitations of DLP solutions (and how to overcome them) DLP…

Defense in depth: Layering your security coverage

2 min read - The more valuable a possession, the more steps you take to protect it. A home, for example, is protected by the lock systems on doors and windows, but the valuable or sensitive items that a criminal might steal are stored with even more security — in a locked filing cabinet or a safe. This provides layers of protection for the things you really don’t want a thief to get their hands on. You tailor each item’s protection accordingly, depending on…

What is data security posture management?

3 min read - Do you know where all your organization’s data resides across your hybrid cloud environment? Is it appropriately protected? How sure are you? 30%? 50%? It may not be enough. The Cost of a Data Breach Report 2023 revealed that 82% of breaches involved data in the cloud, and 39% of breached data was stored across multiple types of environments. If you have any doubt, your enterprise should consider acquiring a data security posture management (DSPM) solution. With the global average…

Cost of a data breach: The evolving role of law enforcement

4 min read - If someone broke into your company’s office to steal your valuable assets, your first step would be to contact law enforcement. But would your reaction be the same if someone broke into your company’s network and accessed your most valuable assets through a data breach? A decade ago, when smartphones were still relatively new and most people were still coming to understand the value of data both corporate-wide and personally, there was little incentive to report cyber crime. It was…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today