A cloud-based identity and access management service for securing user authentication and resource access
Because the Conditional Access policy now requires a registered or compliant device and none exist yet, the tenant admin accounts are effectively locked out by policy misconfiguration.
To recover access:
- Check for another admin who isn’t blocked
If there is any other administrator account that is not affected (for example, excluded from the policy or using a different sign-in path), that admin can:- Sign in to the Microsoft Entra admin center.
- Go to Entra ID > Conditional Access > Policies.
- Locate the misconfigured policy and either:
- Set Enable policy to Report-only, or
- Edit Assignments to exclude at least one admin account (for example, a break-glass account), or
- Temporarily disable or delete the policy.
- If all admins are locked out
If no administrator in the organization can sign in to update Conditional Access policies, the only supported option is to contact Microsoft support so they can adjust the policy:- Follow the guidance to submit a support request.
- Microsoft support will review the situation and, after confirming ownership, update the Conditional Access policies that are preventing access.
- Prevent this in the future
When creating Conditional Access policies that affect all users, always:- Exclude at least one emergency access / break-glass account from the policy so it can be used to recover from lockouts.
- Initially set new policies to Report-only mode, verify impact, and only then switch them to On.
References:
- Troubleshoot sign-in problems with Conditional Access
- Require multifactor authentication for device registration
- Require device compliance with Conditional Access
- Protect security info registration with Conditional Access policy
- Require a compliant device, Microsoft Entra hybrid joined device, or multifactor authentication for all users