conditional policies review

Khalid Hakim 0 Reputation points
2026-05-10T16:46:18.76+00:00

Hello, I created few conditional policies for user sign in and risky users. looking for 2nd review by Microsoft support to make sure its working

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Newest
  1. AI answer

    2026-05-10T16:46:27.8366667+00:00

    Use the built-in monitoring and troubleshooting tools to validate that the Conditional Access policies are working as intended before engaging support.

    1. Review policy impact and report-only results
      • In the Microsoft Entra admin center, open each Conditional Access policy and review the Policy impact tab to see how it affects interactive sign-ins over the last 24 hours, 7 days, or 1 month.
      • If any policies are in Report-only mode, use the Policy impact view and the Conditional Access Insights and Reporting workbook to understand both individual and combined effects before switching them to On.
    2. Validate behavior with sign-in logs
      • Go to Entra IDMonitoring & healthSign-in logs.
      • Filter by Username, Date, Conditional Access, and Resource to find test sign-ins for users covered by the policies.
      • Open a sign-in event and select the Conditional Access tab to see which policies were applied, not applied, or in report-only mode, and why.
      • Use Troubleshooting and support in the event to see specific failure reasons (for example, device not compliant, MFA required, etc.).
    3. Test risk-based policies (risky sign-ins / risky users)
      • Ensure risk-based conditions such as Sign-in risk and User risk are configured in the relevant policies.
      • For risk-based access policies, confirm that:
        • The correct risk levels (for example, medium or high) are selected.
        • The access controls (for example, require multifactor authentication or require password change) match the intended behavior.
      • Use the User sign-ins (non-interactive) and regular sign-in logs to confirm that risk-based policies are evaluated and that users can self-remediate where configured.
    4. Use the “What If” tool for pre-checks
      • In ProtectionConditional AccessPoliciesWhat if, simulate sign-ins for representative users.
      • Select the user, target apps/resources, and run What If to see which policies would apply and what controls would be enforced, without impacting production sign-ins.
    5. Iterate and then enable
      • After confirming expected results via Policy impact, Sign-in logs, and What If, move policies from Report-only to On.
      • Continue to monitor sign-in logs and policy impact for a period after enabling to ensure there are no unintended blocks.

    If a specific sign-in is failing or behaving unexpectedly, capture the Correlation ID and timestamp from the error page, then use that in the sign-in logs to pinpoint exactly which Conditional Access policy caused the behavior and adjust the policy configuration accordingly.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.