Skip to content
Skip to content
theDXT
  • Home
  • IT
  • Scripts
  • GitHub
  • LinkedIn
  • X (Twitter)
  • Search Icon
Microsoft Entra ID Protected Actions

Microsoft Entra ID Protected Actions

September 18, 2026

Microsoft Entra ID has a feature called Protected Actions. When you configure Protected Actions, you can use them with Conditional Access policies to add extra layers of security before the protected action executes.

The following actions can be configured with Protected Actions:

  • Conditional Access policy management
  • Named Location management
  • Protected Actions management
  • Cross-tenant Access policy management
  • Hard deletions of soft-deleted items

In this post, I will show you step by step how to configure Microsoft Entra ID Protected Actions with Conditional Access.

The Process

  • Login to the Microsoft Entra admin center.
  • Click on Entra ID > Conditional Access.
  • Click on Authentication contexts.
  • Click on New authentication context.
  • Enter a name for the Protected Action Authentication context.
  • Select Publish to apps.
  • Pick an ID.

In my example, I will create three authentication contexts: one for Conditional Access policy management, one for Cross-tenant Access policy management, and one for Hard Delete.

Once we have created the authentication contexts, we need to build a Conditional Access policy that uses them.

  • Click on Policies.
  • Click on New policy.
  • Next, we need to configure the Conditional Access policy.
  • For Name, enter the name you want to use for your Conditional Access policy.

In my example, I will call it Protected Actions.

  • For Users, select the users that you want to apply the policy to and select any users you want to exclude.

In my example, I will select all users and exclude my break-glass accounts.

  • For Target resources, select Authentication context.
  • Select the Authentication contexts you want to target with the policy.

In my example, I will select all the Protected Action authentication contexts.

  • For Grant, select what action you want the policy to take.

In my example, I will select Grant access, and Require authentication strength with Phishing-resistant MFA.

  • For Session, decide if you want to apply any session restrictions.

In my example, I will select Sign-in frequency and set it to Every time (5-minute tolerance) to require users to complete MFA again before performing any protected actions.

  • After you configure everything in the Conditional Access policy, click Create.

Now that the Conditional Access policy is built, the next step will be to assign protected actions to the authentication context linked in the policy.

  • Click on Entra ID > Roles & admins.
  • Click on Protected actions.
  • Click on Add protected actions.
  • Select the Conditional Access authentication context that you want to add protected actions to.
  • Click on Select permissions.
  • Select the permissions you want to add to the authentication context, then click Add.

You can add each protected action to only one Authentication context.

  • In my example, the Protected Action – Conditional Access policies authentication context will have the following permissions:
    • microsoft.directory/conditionalAccessPolicies/basic/update
    • microsoft.directory/conditionalAccessPolicies/create
    • microsoft.directory/conditionalAccessPolicies/delete
    • microsoft.directory/namedLocations/basic/update
    • microsoft.directory/namedLocations/create
    • microsoft.directory/namedLocations/delete
    • microsoft.directory/resourceNamespaces/resourceActions/authenticationContext/update
  • In my example, the Protected Action – Cross-tenant Access policies authentication context will have the following permissions:
    • microsoft.directory/crossTenantAccessPolicy/allowedCloudEndpoints/update
    • microsoft.directory/crossTenantAccessPolicy/default/b2bCollaboration/update
    • microsoft.directory/crossTenantAccessPolicy/default/b2bDirectConnect/update
    • microsoft.directory/crossTenantAccessPolicy/default/crossCloudMeetings/update
    • microsoft.directory/crossTenantAccessPolicy/default/tenantRestrictions/update
    • microsoft.directory/crossTenantAccessPolicy/partners/b2bCollaboration/update
    • microsoft.directory/crossTenantAccessPolicy/partners/b2bDirectConnect/update
    • microsoft.directory/crossTenantAccessPolicy/partners/create
    • microsoft.directory/crossTenantAccessPolicy/partners/crossCloudMeetings/update
    • microsoft.directory/crossTenantAccessPolicy/partners/delete
    • microsoft.directory/crossTenantAccessPolicy/partners/tenantRestrictions/update
  • In my example, the Protected Action – Hard Delete authentication context will have the following permission:
    • microsoft.directory/deletedItems/delete
  • Test the new Conditional Access policy.

Even in report-only mode, attempting a protected action will show messages about the additional authentication requirements.

  • Once you’ve completed testing the Conditional Access policy, set Enable policy to On and click Save.

That’s all it takes to configure Microsoft Entra ID Protected Actions with Conditional Access.

You can take Protected Actions a step further and configure a block policy to ensure the actions can only be performed on a certain network and/or system.

If you want to read more about Protected Actions, here is the Microsoft documentation.

Related posts:

Microsoft Entra ID External MFA Microsoft Entra ID Conditional Access What If Microsoft Entra ID Conditional Access Entra ID External Authentication Methods with Duo

IT
Authentication Context, Azure AD, Conditional Access, Entra ID, Hardening, How To, Microsoft, Microsoft 365, Office 365, security

Post navigation

PREVIOUS
I Went to VMware Explore 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

About Me

Daniel Keer

Project Lead, Senior Consultant at Digitally Accurate Inc.

Awards and Certificates
VMware vExpert ⭐⭐⭐⭐
Omnissa Tech Insider ⭐⭐⭐

Consulting

Stuck on something? Reach out to Digitally Accurate Inc. and we can provide expert IT consulting to help you move forward.

  • Microsoft Entra ID Protected Actions
  • I Went to VMware Explore 2026
  • Microsoft Entra ID Governance Access Package Workflow
  • Configure Microsoft Entra ID Governance Entitlement Management Access Packages
  • Microsoft Entra ID Conditional Access What If

Recent Posts

  • Microsoft Entra ID Protected Actions
  • I Went to VMware Explore 2026
  • Microsoft Entra ID Governance Access Package Workflow
  • Configure Microsoft Entra ID Governance Entitlement Management Access Packages
  • Microsoft Entra ID Conditional Access What If
  • Microsoft Entra ID Conditional Access
  • Configure VCF Installer Online Depot
  • Deploy VCF Installer
  • I’m Going to VMware Explore 2026
  • Passing VCP-VCF Architect Exam

Tags

2014 Calgary Certificates Christmas EUC event Firewall holiday How To Microsoft Microsoft 365 Mouthy & Keerious Networking Omnissa podcast Power Loss PowerShell review Script Spoiler Free twelve days of christmas VEDA VEDA 2015 video vlog Vlog Every Day in April VMware Windows youtube yyc

© 2026   Copyright. All Rights Reserved.