Authentication method strategy
Choose supported passkey, certificate and MFA methods for user groups, devices and assurance requirements.
Passkeys & Conditional Access
MAITS designs passkey adoption and Conditional Access as a connected system: registration, authentication strength, device and risk signals, privileged access, recovery and operations.
Strong method + sound registration + proportionate policy + recoverable journey. Weakness in any term changes the outcome.
Authentication architecture
Design scope
Choose supported passkey, certificate and MFA methods for user groups, devices and assurance requirements.
Control how people establish a method, including Temporary Access Pass where appropriate, and monitor registration risk.
Use Conditional Access to require suitable method combinations for sensitive applications and privileged actions.
Design assisted and self-service recovery so the weaker fallback does not negate the stronger primary method.
Combine phishing-resistant authentication, dedicated admin identities, PIM and protected workstations where justified.
Pilot representative cohorts, measure failure modes, maintain emergency access and phase policy enforcement.
Conditional Access
Conditional Access evaluates identity, application, device, location, risk and other supported signals after first-factor authentication, then applies grant, block or session controls.
MAITS helps reduce overlapping policies, define exclusions and emergency access, map authentication strengths to risk, use report-only evidence and plan enforcement without accidental lockout.
Microsoft Conditional Access overviewAccess decision
Conditional Access is easier to govern when policies are organised around personas, resources and control intent rather than accumulated one-off exceptions.
Method architecture
Plan device-bound or synced platform experiences and roaming FIDO2 security keys for the relevant populations.
Treat WHfB and Microsoft Entra passkeys as related but distinct credentials, policy surfaces and user journeys.
Use time-limited bootstrap where appropriate to establish strong methods without leaving enrolment as the weakest path.
Design lost-device, replacement, help-desk and privileged recovery so fallback assurance remains proportionate.
Conditional Access engineering
Rollout pattern
Inventory methods, applications, populations, device state, exclusions and recovery paths.
Define target methods, authentication strengths, policy intent and exception handling.
Test enrolment, sign-in, device variation, lost-device recovery and support scenarios.
Roll out by cohort with monitoring, explicit decision points and operational ownership.
Start a conversation
Plan the methods, policies and recovery controls as one identity architecture.