A cloud-based identity and access management service for securing user authentication and resource access
Use the built-in monitoring and troubleshooting tools to validate that the Conditional Access policies are working as intended before engaging support.
- Review policy impact and report-only results
- In the Microsoft Entra admin center, open each Conditional Access policy and review the Policy impact tab to see how it affects interactive sign-ins over the last 24 hours, 7 days, or 1 month.
- If any policies are in Report-only mode, use the Policy impact view and the Conditional Access Insights and Reporting workbook to understand both individual and combined effects before switching them to On.
- Validate behavior with sign-in logs
- Go to Entra ID → Monitoring & health → Sign-in logs.
- Filter by Username, Date, Conditional Access, and Resource to find test sign-ins for users covered by the policies.
- Open a sign-in event and select the Conditional Access tab to see which policies were applied, not applied, or in report-only mode, and why.
- Use Troubleshooting and support in the event to see specific failure reasons (for example, device not compliant, MFA required, etc.).
- Test risk-based policies (risky sign-ins / risky users)
- Ensure risk-based conditions such as Sign-in risk and User risk are configured in the relevant policies.
- For risk-based access policies, confirm that:
- The correct risk levels (for example, medium or high) are selected.
- The access controls (for example, require multifactor authentication or require password change) match the intended behavior.
- Use the User sign-ins (non-interactive) and regular sign-in logs to confirm that risk-based policies are evaluated and that users can self-remediate where configured.
- Use the “What If” tool for pre-checks
- In Protection → Conditional Access → Policies → What if, simulate sign-ins for representative users.
- Select the user, target apps/resources, and run What If to see which policies would apply and what controls would be enforced, without impacting production sign-ins.
- Iterate and then enable
- After confirming expected results via Policy impact, Sign-in logs, and What If, move policies from Report-only to On.
- Continue to monitor sign-in logs and policy impact for a period after enabling to ensure there are no unintended blocks.
If a specific sign-in is failing or behaving unexpectedly, capture the Correlation ID and timestamp from the error page, then use that in the sign-in logs to pinpoint exactly which Conditional Access policy caused the behavior and adjust the policy configuration accordingly.
References:
- Microsoft-managed Conditional Access policies
- Conditional Access policies for Windows 365 Link
- Conditional Access for agents operating on-behalf-of a user in Microsoft Entra
- Risk-based access policies
- Analyze Conditional Access Policy Impact
- Conditional Access: Conditions
- Conditional Access for Surface Hub
- Troubleshoot sign-in problems with Conditional Access