Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To find Microsoft’s new managed Conditional Access policies, open the Microsoft Entra admin center and go to Entra ID > Conditional Access > Policies. If your tenant is eligible, Microsoft-managed policies appear there in Report-only state so you can review their effect before enforcement. Business Premium includes Entra ID P1 Conditional Access features, but the policies available and their rollout timing depend on your tenant and the individual policy.

What Microsoft-managed Conditional Access does

Conditional Access evaluates who is signing in, what resource they are accessing, and relevant context such as device or location. It can then require a control, apply a session control, or block access. Microsoft-managed policies are preconfigured policies that Microsoft creates and maintains for eligible tenants.

Microsoft’s documented examples include policies that block legacy authentication or device code flow, require multifactor authentication (MFA) for users or administrators accessing Microsoft admin portals, and address certain risky sign-ins. The policy set can change, and not every policy applies to every tenant or license. Check what is actually listed in your tenant.

These managed policies are different from policy templates. A template is a starting point for an administrator-created policy; a managed policy is controlled and maintained by Microsoft. Managed policies have limited tenant controls: you can change their state and exclude identities, but you cannot rename or delete them. If you need different conditions or broader customization, duplicate the managed policy and manage the duplicate as a regular Conditional Access policy. Review the duplicate’s coverage carefully so customization does not weaken protection. Microsoft’s managed-policy documentation describes these controls.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • ABIS BOOK

Check licensing and prerequisites

  • Licensing: Microsoft 365 Business Premium includes Microsoft Entra ID P1 Conditional Access features. Entra ID P1 or P2 is generally required for Conditional Access; risk-based policies that use Entra ID Protection require P2. Confirm the subscription assigned to your tenant and the requirements for each policy. See Microsoft’s Microsoft 365 MFA setup guidance and Conditional Access deployment planning guidance.
  • Administrative role: Microsoft identifies Conditional Access Administrator as the least-privileged role for viewing managed policies. Other tasks may require the corresponding administrative permissions.
  • Test identities: Before building or enforcing custom policies, prepare a non-admin test user and pilot group, identify emergency-access accounts, and make sure users have registered the authentication methods they will need.
  • Security defaults: Security defaults and Conditional Access cannot be active together. Do not disable security defaults until you have a plan to replace the protections your organization relies on.

Find and review the managed policies

  1. Sign in to the Microsoft Entra admin center with an appropriately privileged account.
  2. Open Entra ID > Conditional Access > Policies.
  3. Look for policies identified as Microsoft-managed. Open each policy and review its purpose, state, eligible scope, exclusions, and any tenant-specific rollout notice. Names and availability can vary as Microsoft updates the policy set.
  4. Open the policy’s Policy impact view to assess expected effects. Also review sign-in records at Entra ID > Monitoring & health > Sign-in logs. Filter by Conditional Access and, as needed, user, date, or correlation ID; open a sign-in event to inspect its Conditional Access evaluation.

Understand Report-only and automatic rollout

Report-only lets you assess how a policy would affect sign-ins without applying its grant or block result. It is a review state, not necessarily a permanent opt-out. Microsoft says policies left in Report-only are enabled no sooner than 45 days after introduction, with email and Microsoft 365 Message Center notice 28 days beforehand. Microsoft also says some policies may be enabled faster when that timing is communicated for the tenant. Treat the state and notices shown for your tenant as authoritative, and review the policy details rather than assuming Report-only will remain unchanged. Microsoft explains the managed-policy rollout behavior here.

For a managed policy, review impact and exclusions, then change its state only in line with your organization’s rollout plan and the tenant’s notices. If you need controls that the managed version does not offer, duplicate it and test the separately managed policy before applying it broadly.

Protect emergency access and avoid lockouts

Keep designated emergency-access or break-glass accounts out of policies that could prevent administrators from recovering access. Microsoft recommends at least two emergency-access administrator accounts when creating a custom MFA baseline. Avoid making an everyday administrator the only excluded identity. Confirm that the exclusions work as intended and that emergency access is not dependent on the same sign-in requirement the policy enforces.

Exclusions need deliberate review: multiple Conditional Access policies can apply to one sign-in, so excluding a user from one policy does not necessarily exempt that user from every other policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you are switching from security defaults

Security defaults provide a simpler baseline for tenants without Entra ID P1 or P2. Conditional Access offers more granular controls, but it requires eligible licensing and policy planning. Because the two approaches cannot be enabled together, switching means replacing the protections you need—not merely turning defaults off.

  1. Identify the protections currently supplied by security defaults and decide which equivalent controls your organization needs.
  2. Prepare the replacement Conditional Access policies before making the transition. Microsoft’s MFA setup guidance includes templates for MFA for all users, MFA for administrators, blocking legacy authentication, and MFA for Azure management.
  3. Adjust exclusions after creating policies, including appropriate emergency-access accounts. Review who and what each policy covers.
  4. Use Report-only mode with pilot users, inspect policy impact and sign-in logs, and make corrections before enforcement.
  5. Turn off security defaults as part of the planned transition, then complete and monitor the Conditional Access configuration.

Do not disable security defaults first and leave the tenant without a prepared replacement baseline. For setup details, consult Microsoft’s MFA setup instructions.

Test custom policies before enforcement

For administrator-created policies, Microsoft recommends using Report-only mode and testing with a pilot group. Keep each policy in Report-only for at least one week before enforcing it, then review sign-in activity and policy impact. Check both included users and exclusions, and test the user and access scenarios the policy is meant to cover. Microsoft’s deployment planning guide provides additional planning guidance.

  • Start with a small pilot that includes representative user and sign-in scenarios.
  • Confirm that required authentication methods are registered before enforcing an MFA requirement.
  • Check sign-in logs for unexpected grants, blocks, or unmet controls.
  • Tell affected users what will change and how to get help.
  • After rollout, continue reviewing sign-in activity and policy results.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot an unexpected sign-in result

When a user is blocked or prompted unexpectedly, gather the affected user, sign-in time, target application, client type, operating system, and correlation ID. In Entra ID > Monitoring & health > Sign-in logs, open the relevant event and inspect its Conditional Access details to identify which policies applied and what result each produced. Use that evaluation to determine whether the cause is policy scope, an exclusion, a grant requirement, or the sign-in context before changing policy settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Managed policies, custom policies, and security defaults

Option Who maintains it Control and fit Key consideration
Security defaults Microsoft provides the baseline. A simpler security baseline for tenants without Entra ID P1 or P2; it offers less granular control than Conditional Access. Cannot be active at the same time as Conditional Access. Plan replacement protections before switching.
Microsoft-managed Conditional Access policy Microsoft creates and maintains the policy. Tenant administrators can change state and exclude identities, but cannot rename or delete it. Availability and rollout depend on tenant eligibility and policy details; Report-only may be followed by automatic enablement.
Administrator-created Conditional Access policy Your organization manages the policy. Can be built from a template or a duplicate of a managed policy to address requirements beyond Microsoft’s managed settings. Requires eligible licensing, careful scoping, testing, and ongoing review.

Frequently confused points

  • Business Premium is not the same as every Entra feature: it includes Entra ID P1 Conditional Access features, but risk-based Conditional Access using Entra ID Protection requires P2.
  • A managed policy is not a template: Microsoft maintains the managed policy; an administrator manages a policy created from a template or duplicate.
  • Report-only is not a guarantee of permanent inactivity: follow the state and notices presented in your tenant.
  • More customization creates more operational responsibility: test policy interactions and preserve a recovery path before broad enforcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.