Tag not monitored by Microsoft.
If sign-in is blocked for all users, including administrators, by a Conditional Access policy, the policy cannot be removed directly from the portal. Use the following supported recovery paths:
- Check for any unblocked admin or emergency access account
- If there is another administrator or a break-glass/emergency access account that is not affected by the policy, sign in with that account.
- In the Microsoft Entra admin center, go to Entra ID → Protection → Conditional Access and disable or edit the policy that is blocking sign-in.
- If all admins are locked out
- When no administrator can sign in to update Conditional Access, a support request with Microsoft is required.
- Follow the documented guidance to submit a support request so Microsoft Support can review and, after confirming ownership, update or disable the Conditional Access policies that are preventing access.
- Prevent future lockouts
- Configure at least one emergency access (break-glass) account and exclude it from Conditional Access policies so it can always sign in and recover access if a policy is misconfigured.
References:
- Troubleshoot sign-in problems with Conditional Access
- Apply Conditional Access policies to Global Secure Access traffic
- Apply Conditional Access policies to Private Access apps
- Require multifactor authentication for all users
- Conditional Access policy templates
- Block access by location
- Block authentication flows with Conditional Access policy