# What specific conditions can be used to build conditional access policies?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Conditional access policies are becoming a must-have for organizations looking to tighten security without making things harder for users. With platforms like <a class="a a--md" elv="true" href="https://www.g2.com/products/jumpcloud/reviews">JumpCloud</a>, there are often a variety of conditions you can set—like user group, device trust status, location, network, time of day, or even how sensitive an application is.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"> A big question is just how granular these rules can get. In some setups, multiple conditions can be combined to create very specific access requirements. For example, a policy might allow access only for members of a certain group, on trusted devices, from a certain location, and only during work hours.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"> Helpful features often include:</p><ul>
<li>Conditions based on user role or group</li>
<li>Checks for device trust or compliance</li>
<li>Location or network-based restrictions</li>
<li>Sensitivity level of the application</li>
<li>Options to layer multiple conditions for more precise control</li>
<li> How flexible are JumpCloud’s conditional access policies in real-world use? Any examples or best practices for combining conditions to get the right balance of security and convenience?</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: about 1 year ago
- Author title: Industry Analyst
- Net upvotes: 3


## Comments
### Comment 1

&lt;p&gt;Combining user group and device trust makes it easier to block risky sign-ins.&lt;/p&gt;

##### Comment Metadata
- Posted at: about 1 year ago
- Author title: Industry Analyst
- Net upvotes: 1


### Comment 2

&lt;p&gt;&lt;span style=&quot;color: rgb(0, 0, 0);&quot;&gt;JumpCloud&#39;s conditional access policies offer flexibility to build highly granular access rules. These include user group membership, allowing you to tailor policies to different departmental or role-based needs. Device trust is another powerful condition. You can verify if a device is managed by JumpCloud, if it possesses a valid device trust certificate, or if essential security features like disk encryption are active. This helps distinguish between trusted corporate devices and potentially unmanaged personal devices.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: rgb(0, 0, 0);&quot;&gt;Beyond user and device attributes, contextual conditions are also available. These include location, which can be defined by specific IP address ranges (e.g., your office network) or by geographic regions. Network conditions allow you to differentiate between trusted internal networks and untrusted external networks, like public Wi-Fi. Policies can also be time-based, restricting access to certain times of the day.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 12 months ago
- Author title: Manager





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: about 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: about 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: about 13 years ago
  - Comments: 4


