Why this matters
Conditional Access is where zero trust actually gets enforced in Microsoft 365, and it is easy to get subtly wrong: a policy left in report-only, admins accepting phishable MFA, legacy protocols never blocked, or no break-glass exclusion on a block-everyone rule.
Reading JSON is how those mistakes survive review. Plain English, plus a coverage check across the whole set, makes them obvious.