Access denied?
Follow the decision.
A structured investigation for authentication and Conditional Access failures across identity, device, risk and application controls.
Start with the log
Capture the exact timestamp, user, application, resource, client, correlation details and sign-in result before changing policy.
Find the decision
Identify which Conditional Access policies applied, which controls were required and which condition produced the block.
Validate trust
Check device identity, join state, compliance and management signals when access depends on a managed endpoint.
Trace the access decision.
Sign-in result
Separate authentication failure from Conditional Access failure. The remediation path is different.
Effective policy
Record the policies that applied and the specific grant, block or session control involved.
Device signal
When required, correlate Entra device state with Intune compliance and the endpoint actually used.
Do not disable Conditional Access as a first response. Establish whether the failure is authentication, policy evaluation, device compliance, risk, application configuration or an upstream dependency. Remediate the demonstrated cause, then reproduce the original access scenario to verify.