Conditional access is an access control method that grants or denies entry to a system based on a set of conditions, not just a matching username and password. Every login attempt is evaluated by its context, including who is logging in, what device they are using, and where the login is coming from.
Stolen credentials remain the most exploited weakness for attackers. Verizon’s 2025 Data Breach Investigations Report found that 88% of attacks against basic web applications involved stolen credentials, meaning a correct password alone is no longer enough to confirm that whoever is logging in is actually authorized.
This is where conditional access comes in, adding a layer of contextual evaluation before access is actually granted. This article covers how conditional access works, why it matters for company data security, and the practical steps for implementing it.
What Is Conditional Access?
Traditional access control is static. Once a username and password match, the system grants full access without weighing any other context around the request.
Conditional access turns this into a conditional decision, using an if-then principle that evaluates four main factors before an access decision is made. This approach is part of the Zero Trust security framework, which starts from the assumption that no access request is automatically trusted, even one originating from inside the company’s own network.
How Does Conditional Access Work?
In simple terms, conditional access works through a policy engine that checks four main signals every time someone attempts to log in, then matches them against rules the company has already set. Based on that match, the system will allow, block, or request additional verification before access is actually granted.

User or Group Identity
The system checks who is logging in and the access level tied to that account, for instance whether the account can reach financial data or customer data. The more sensitive the data an account can reach, the stricter the rules applied to it.
A login from an account with access to financial data, for example, is usually asked for additional verification through MFA automatically. An account with limited access to general information usually goes through with a standard login only.
Device Compliance Status
The system checks whether the device being used is registered with the company’s management system and meets basic security standards, such as encryption and running an operating system that still receives security updates. This information typically comes from a security agent installed on the device or the company’s device management platform.
Devices that fail to meet these requirements are either blocked entirely or limited to non-sensitive applications. An officially registered company device that stays up to date usually gets full access without extra friction.
Location and IP Address
The system compares the current login location with the pattern a user normally logs in from, including the country and network commonly used for work. An unusual location shift, such as a login from two different countries within a time frame that would be physically impossible to travel, is the signal the system flags most easily.
A login from a country the user does not normally use triggers additional verification, while a login from an already recognized location usually goes through without friction. A stricter policy can even block access outright from countries considered high risk, skipping the additional verification step altogether.
Session Risk Level
The system also evaluates the risk level of the login session itself through a pattern detection engine, separate from the three signals above. This assessment compares the current login pattern against the user’s usual behavior in real time to catch activity that looks out of place.
The most common example is two login locations recorded far apart within a short window of time, which the system flags as possible session or credential theft. A risk score this high usually triggers an automatic block and an alert to the admin right away, without waiting for manual confirmation.
Learn Zero Trust Security
Zero Trust Security is a security strategy that has become an urgent need for organizations amidst the high risk of cyber attacks and access abuse.
Zero Trust Security
Deepen your understanding of Zero Trust Security and learn its principles and implementation in depth by downloading this PDF. Your data security is our priority.
Why Does Conditional Access Matter for Company Data Security?
Conditional access matters because today’s cyberattacks rarely start from a complex technical vulnerability. They typically start from credentials stolen through phishing or a third party breach, the exact pattern the Verizon data above shows across most web application attacks.
For companies handling the personal data of people in Indonesia, Article 35 of Indonesia’s Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”) requires data controllers to build and apply technical measures that protect personal data from processing that breaches the law. As with the PDP Law’s other obligations, this applies extraterritorially, so a foreign company processing the personal data of people in Indonesia is bound by the same requirement even without a local entity.
Article 39(1) of the same law goes further, explicitly requiring the prevention of unauthorized access to personal data, and a legal review by Hukumonline confirms this obligation extends to data processors as well, not only controllers. Conditional access is one concrete way to satisfy both requirements, since every access attempt to a system holding personal data gets evaluated before it is actually let through.
Real-World Scenarios for Conditional Access
Conditional access is easier to understand through scenarios that come up often in a typical workplace. The four examples below show how the system responds to different situations automatically.
- Login from an unusual location. A finance team member tries to log in from abroad while on leave. The system detects the unfamiliar location and asks for additional verification before allowing access to transaction data.
- Access from a personal device. A marketing team member opens the company dashboard from a personal laptop that is not registered. Conditional access limits that session to non-sensitive applications until the device is registered and meets the security standard.
- Activity outside normal working hours. A system admin tries to log into the customer database server at two in the morning, well outside normal working hours. The system flags this as an anomaly and sends a verification request to the admin’s registered device before granting access.
- A former employee’s account. An account belonging to an employee who already left the company still attempts to log into the corporate email. Since that account’s status is already deactivated in the identity policy, the system blocks access automatically without any manual intervention.
How to Implement Conditional Access at Your Company
Implementing conditional access does not need to start with a complicated policy on day one. The four steps below are the practical sequence most companies follow when they begin adopting it.
1. Identify the Highest-Risk Applications and Data
The first step is mapping out which applications and systems hold the most sensitive data, such as financial data, customer data, or employee data. These highest-risk applications should get the strictest conditional access policy first.
2. Set a Risk Level for Each Access Scenario
Every signal combination, such as a foreign location or an unregistered device, needs a risk weight so the system knows when to respond more strictly. Companies can start with three simple categories, low, medium, and high risk, before building more detailed rules.
3. Roll Out the Policy in Stages
A policy should be piloted on one team or one application first before rolling out company-wide, so its impact on day-to-day work can be properly evaluated. Applying every rule at once across the whole organization risks disrupting operations when employees suddenly get locked out of systems they use regularly.
4. Monitor and Adjust the Policy Regularly
Access patterns and cyber threats keep changing, so a conditional access policy needs regular review rather than being set once and left alone. Logs of blocked or flagged access attempts are the most useful source of information for refining the next round of rules.
Conclusion
Conditional access is a concrete step toward smarter access control, evaluating the context of every login instead of relying only on a username and password match. This approach also helps companies meet the personal data security obligations set out in Indonesia’s PDP Law, particularly around preventing unauthorized access.
Implementing it does not have to be complicated from the start, since a company can begin with its highest-risk applications and expand the policy in stages. What matters most is making sure the policy keeps getting monitored and adjusted as threat patterns continue to evolve.
Ready to Manage Digital Identities as a Business Security Strategy?
Request a demo today and discover how IAM solutions centralize user logins through Single Sign-On (SSO), automate employee onboarding, and protect company data from unauthorized access without disrupting productivity with repeated logins.
FAQ
MFA is one form of additional verification, while conditional access is the system that decides when MFA needs to be requested. Conditional access can require, skip, or add other verification layers depending on the login context.
It can, if the policy is too strict or has not been piloted before rolling out company-wide. That is why a policy should be built in stages and adjusted based on how access actually happens in practice.
Yes, since company size does not reduce the risk of credentials being stolen or misused. Small companies are often even more exposed, since they typically do not have a large cybersecurity team.
No. Conditional access complements passwords rather than replacing them, since the combination of both makes identity verification far harder to break.
The PDP Law does not name conditional access specifically, but Article 35 and Article 39 require data controllers to apply technical measures that prevent unauthorized access to personal data. Conditional access is one concrete way to meet that requirement.




