RCA / ENTRA ID / CONDITIONAL ACCESS

Access denied?
Follow the decision.

A structured investigation for authentication and Conditional Access failures across identity, device, risk and application controls.

Start with the log

Capture the exact timestamp, user, application, resource, client, correlation details and sign-in result before changing policy.

Find the decision

Identify which Conditional Access policies applied, which controls were required and which condition produced the block.

Validate trust

Check device identity, join state, compliance and management signals when access depends on a managed endpoint.

INVESTIGATION FLOW

Trace the access decision.

01Sign-in
02Auth
03CA
04Device
05Risk
06App
07Verify

Sign-in result

Separate authentication failure from Conditional Access failure. The remediation path is different.

Effective policy

Record the policies that applied and the specific grant, block or session control involved.

Device signal

When required, correlate Entra device state with Intune compliance and the endpoint actually used.

Root-cause rule

Do not disable Conditional Access as a first response. Establish whether the failure is authentication, policy evaluation, device compliance, risk, application configuration or an upstream dependency. Remediate the demonstrated cause, then reproduce the original access scenario to verify.