Driek Desmet

Driek Desmet

Driek Desmet focuses on Microsoft security, governance and compliance within enterprise environments. His work centres on identity security, Microsoft 365 protection, risk management and regulatory alignment such as NIS2. Through independent analysis and field experience, he explores how organisations can design secure and compliant Microsoft cloud architectures across Entra, Purview, Defender and Intune.
Swiss cheese model applied to identity security

Exploring Conditional Access Bypasses in Microsoft Entra ID

Conditional Access is the backbone of Zero Trust in Microsoft Entra ID, yet real world attacks increasingly demonstrate how it can be bypassed. From device and token abuse to built in exclusions and misunderstood session controls, attackers exploit gaps that many organisations assume are protected.

Triggered by Microsoft’s upcoming change in February 2026, where session revocation will finally behave as expected during incident response, this blog analyses observed Conditional Access bypass techniques from real incidents in 2024 and 2025. More importantly, it explains why a strong security baseline is essential to compensate for what Conditional Access was never designed to solve alone.

Interian | Securing Insights

Require Risk Remediation: The Game-Changer for Conditional Access Policies

Discover the game-changing 'Require Risk Remediation' control in Microsoft Entra Conditional Access. This preview feature simplifies risk management by handling both password and passwordless users in one policy, reducing complexity and misconfigurations. Get a step-by-step guide, real-world benefits, and pragmatic insights into its limitations for enhanced security.