# Conditional Access deployment review

## Scope and ownership
- [ ] Policy display name, object ID and change owner are recorded
- [ ] Business objective and protected resources are explicit
- [ ] Included users, groups, roles and workload identities are reviewed
- [ ] Exclusions have an owner, justification and review date

## Safety controls
- [ ] Two emergency-access accounts are excluded and tested
- [ ] Policy dependencies do not block the rollback operator
- [ ] A pilot group represents target device, location and client conditions
- [ ] Rollback trigger and authority are agreed before enforcement

## Conditions and grant controls
- [ ] Target resources and authentication context are correct
- [ ] Device platform, client app, location and risk conditions are intentional
- [ ] Authentication strength and session controls match the objective
- [ ] Service identities and non-interactive flows have been considered

## Report-only validation
- [ ] Report-only results cover a representative observation period
- [ ] Expected successful and blocked sign-ins were reproduced
- [ ] Unexpected impact has an owner and resolution
- [ ] Sign-in logs retain the policy result and failure reason

## Enforcement
- [ ] Change window, communications and support escalation are ready
- [ ] Policy revision is captured immediately before enablement
- [ ] Post-enable tests cover emergency, administrator and standard-user paths
- [ ] Review date and exception expiry are recorded
