Additional Microsoft Entra services and features related to identity, access, and network security
Error 1189 indicates that the Conditional Access policy is not editable and must be handled by Microsoft. The message “You cannot change the properties of this policy. Reach out to your Microsoft contact for further help.” means the policy is effectively locked from tenant-side modification, including name changes, exclusions, or other property edits.
The only supported remediation path in this situation is to engage Microsoft support so they can review and, if appropriate, update or remove the policy on the backend:
- If there are any other admins in the tenant who still have access to Conditional Access and are not blocked by this policy, have one of them confirm that the policy cannot be edited or disabled from the Microsoft Entra admin center under Entra ID > Conditional Access.
- If no admin can modify or disable the policy, open a support request with Microsoft:
- Follow the guidance in How to get support to submit a support request.
- Provide the policy name, policy ID, template ID, the full error text including code 1189, and recent sign-in details (Request ID, time, and date from affected sign-in events) so support can locate the exact policy and its impact.
- While working with support, use the sign-in logs and Conditional Access details to document the impact:
- In Microsoft Entra admin center, go to Entra ID > Monitoring & health > Sign-in logs.
- Open a failed sign-in, review Basic info and Conditional Access tabs to confirm this specific policy is being applied and blocking access.
- Include these details (especially Request ID and timestamp) in the support case to speed investigation.
Because the platform is explicitly blocking tenant-side edits to this policy, only Microsoft support can change or remove it.
References: