Conditional Access enforcement change coming to Microsoft Entra

Source: Help Net Security

Author: Sinisa Markovic

URL: https://www.helpnetsecurity.com/2026/01/29/microsoft-entra-conditional-access-policy-enforcement/

Conditional Access enforcement change coming to Microsoft Entra

ONE SENTENCE SUMMARY:

Microsoft will enforce Conditional Access policies for all resources, affecting certain client applications, starting March 2026.

MAIN POINTS:

  1. Enforcement change begins March 27, 2026, with rollout through June 2026.
  2. Affects sign-ins via client apps requesting only OIDC or limited directory scopes.
  3. Enforced during sign-in even with resource exclusions in policies.
  4. Users may receive Conditional Access challenges like MFA or device compliance.
  5. Enforcement depends on access controls configured in target policies.
  6. Applies to tenants with policies targeting all resources and exclusions.
  7. Tenants lacking this specific policy configuration remain unaffected.
  8. Swaroop Krishnamurthy provided details on this change.
  9. Azure AD Graph explicitly mentioned as a target resource.
  10. Change aims to enhance security measures across Microsoft Entra.

TAKEAWAYS:

  1. Prepare for enforcement changes starting March 2026.
  2. Review Conditional Access policies with resource exclusions.
  3. Anticipate increased security challenges during sign-ins.
  4. Understand impact on client apps with specific scope requests.
  5. Monitor updates and adapt policies as needed for compliance.