Passkeys & Conditional Access

Phishing-resistant access needs
more than a new sign-in method.

MAITS designs passkey adoption and Conditional Access as a connected system: registration, authentication strength, device and risk signals, privileged access, recovery and operations.

The control equation

Strong method + sound registration + proportionate policy + recoverable journey. Weakness in any term changes the outcome.

Authentication architecture

Protect the whole journey, not only the successful sign-in.

ENROLIdentity proof & bootstrap
+
AUTHENTICATEPasskey / strong method
+
DECIDEConditional Access
+
RECOVERSafe re-establishment

Design scope

Every path into the account deserves scrutiny.

METHODS

Authentication method strategy

Choose supported passkey, certificate and MFA methods for user groups, devices and assurance requirements.

REGISTRATION

Bootstrap and enrolment

Control how people establish a method, including Temporary Access Pass where appropriate, and monitor registration risk.

POLICY

Authentication strengths

Use Conditional Access to require suitable method combinations for sensitive applications and privileged actions.

RECOVERY

Account recovery

Design assisted and self-service recovery so the weaker fallback does not negate the stronger primary method.

PRIVILEGE

Administrator protection

Combine phishing-resistant authentication, dedicated admin identities, PIM and protected workstations where justified.

ROLLOUT

Adoption and assurance

Pilot representative cohorts, measure failure modes, maintain emergency access and phase policy enforcement.

Conditional Access

Signals inform policy. Policy must express intent.

Conditional Access evaluates identity, application, device, location, risk and other supported signals after first-factor authentication, then applies grant, block or session controls.

MAITS helps reduce overlapping policies, define exclusions and emergency access, map authentication strengths to risk, use report-only evidence and plan enforcement without accidental lockout.

Microsoft Conditional Access overview

Access decision

Combine method strength with the context of the request.

Conditional Access is easier to govern when policies are organised around personas, resources and control intent rather than accumulated one-off exceptions.

Context-aware access decisionIdentity, device, authentication, risk, role and context feed a policy decision that can allow, require a stronger method, limit a session or deny access.IDENTITYDEVICEAUTHENTICATIONRISKROLECONTEXTPOLICY DECISIONProportionate accessALLOWSTEP-UPLIMITDENY
A coherent policy model evaluates supported signals together and makes exclusions, emergency access and operational evidence explicit.

Method architecture

Passwordless is a system, not a credential rollout.

PASSKEYS

Platform and roaming

Plan device-bound or synced platform experiences and roaming FIDO2 security keys for the relevant populations.

WINDOWS

Windows Hello for Business

Treat WHfB and Microsoft Entra passkeys as related but distinct credentials, policy surfaces and user journeys.

BOOTSTRAP

Temporary Access Pass

Use time-limited bootstrap where appropriate to establish strong methods without leaving enrolment as the weakest path.

RECOVERY

Re-establish trust

Design lost-device, replacement, help-desk and privileged recovery so fallback assurance remains proportionate.

Conditional Access engineering

Control policy sprawl before it becomes an outage risk.

Rollout pattern

Prove the journey before enforcing the policy.

01

Baseline

Inventory methods, applications, populations, device state, exclusions and recovery paths.

02

Design

Define target methods, authentication strengths, policy intent and exception handling.

03

Pilot

Test enrolment, sign-in, device variation, lost-device recovery and support scenarios.

04

Enforce

Roll out by cohort with monitoring, explicit decision points and operational ownership.

Start a conversation

Make strong authentication usable — and resilient.

Plan the methods, policies and recovery controls as one identity architecture.