A water-lab nearly locked operators out of the Azure portal the last time a Conditional Access policy for Azure management went straight to On. What should the security engineer do before enforcing the new policy?
Select an answer to reveal the explanation.
Short Explanation
Flip the big red On switch first and you may lock the whole lab out of Azure. Park the policy in report-only, watch who would have been blocked, then turn it On when the numbers look sane—same idea as a dry run before a change window.
Full Explanation
Report-only lets Conditional Access evaluate Azure management (and other cloud apps) without enforcing blocks or grants, so teams can measure impact in sign-in logs before enforcement. Enabling On without that review risks locking operators out, which matches the lab’s prior incident. Sentinel analytics observe after the fact and do not replace report-only enablement. Break-glass accounts should remain excluded and available, not disabled for reporting convenience.