How to Review and Customize Microsoft-Managed Conditional Access Policies
Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.
Microsoft automatically creates Conditional Access policies in many tenants. Here is how to review them, customize them safely and make sure they fit with your existing policies.
Step 1: Find the policies
In the Entra admin center, open Protection → Conditional Access → Policies. Microsoft-managed policies are labeled as created by Microsoft. Each has a description and an expected enablement date if still in report-only mode.
Step 2: Review impact
For each managed policy:
- Check report-only results in sign-in logs (Conditional Access tab, report-only results).
- Identify users who would be prompted or blocked.
- Compare with your existing policies — is it redundant, stricter or weaker?
Step 3: Customize where needed
You can typically:
- Exclude specific users or groups (always exclude break-glass accounts).
- Change state (report-only, on or off) — though Microsoft recommends keeping them on unless you have equivalent or stronger policies.
You generally cannot change the core conditions or controls of a Microsoft-managed policy. If you need different logic, duplicate it into a custom policy and adjust that.
Step 4: Avoid conflicts
Conditional Access applies all matching policies. A managed policy requiring MFA won't conflict with a stricter custom policy requiring phishing-resistant MFA — the stricter control still applies. But exclusions in one policy don't override requirements in another.
Step 5: Document decisions
Record why you kept, excluded or disabled each managed policy. Auditors and future administrators will ask.
Step 6: Watch for new ones
Microsoft adds managed policies over time. Monitor Message Center and the Conditional Access blade quarterly.
- Secure Future Initiative and Microsoft-Managed Conditional Access Policies (Nov 2023) Platform Changes
- Conditional Access Policy Review Checklist How-To & Hardening
- CIO Brief: Microsoft Is Changing Your Defaults — Here's What to Know CIO Briefings