Instead of treating a successful sign-in as sufficient for every request, policy can consider the identity, authentication strength, device state, resource sensitivity, requested action, network context, time, behavior, and current threat information.
Evaluation may occur at sign-in, when a sensitive action is requested, and during an active session. A decision can require stronger authentication, limit available functions, shorten a session, place the user in a restricted environment, or revoke access. The exact signals and responses depend on the organization’s risk model rather than a universal product setting.
Key points
Common signalsUser and workload identity, device health, credential or authenticator strength, location, behavior, resource classification, and threat indicators.
Possible responsesAllow, deny, require step-up authentication, restrict capabilities, demand a managed device, or re-evaluate and terminate a session.
Sound operationTest policies against real workflows, protect emergency access, log decisions, monitor signal quality, and design for identity-provider or network failures.
Important limitationContextual signals can be stale, spoofed, or simply wrong. Overly broad policies can lock out legitimate users, while permissive exceptions can become durable bypasses.