Skip to content

Update Conditional Access Policy

Azure

Update Conditional Access Policy

service: Azure - Microsoft Entra ID
techniques:

Event

Changes policy assignments, conditions, grant/session controls, or state. An exclusion removes a user from this policy’s scope, not from every authentication requirement. All other applicable enabled policies and service requirements still matter; report-only and disabled policies have different effects.

Security Context

Unauthorized exclusions can modify authentication defenses (T1556.009). Approved emergency-access design and policy maintenance can produce similar changes. A policy name or one exclusion does not prove password-only access or a successful sign-in.

Log Source

Microsoft Entra directory audit logs, illustrated with activityDisplayName: Update conditional access policy. Match result, actor, and target IDs. Graph-style exports and Azure Monitor wrappers differ; exact modified-property and additionalDetails serialization still needs captured-log validation.

Key Fields

FieldInvestigation value
activityDisplayName, resultRecorded activity and outcome.
initiatedBy, correlationIdActor and related changes; verify actual administrative authority.
targetResourcesTarget ID/type and illustrative old/new properties.
additionalDetailsOptional method/client context; do not assume all exports expose full values.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Compare full old/new policy JSON, including state, included roles, applications, exclusions, and controls.
  3. Verify approval and evaluate all applicable policies and the user’s actual role/assignment context.
  4. Correlate sign-in Conditional Access results and authentication details before claiming MFA bypass.

Sample Event

Synthetic scenario. The sample adds Draco to excludeUsers while retaining an existing exclusion. It shows one policy edit, not a sign-in or removal of every MFA requirement.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000100011110_8F3D9_71022874",
"category": "Policy",
"correlationId": "90000000-0000-4000-8000-000100011110",
"result": "success",
"resultReason": "",
"activityDisplayName": "Update conditional access policy",
"activityDateTime": "2026-04-15T18:14:55.4128088Z",
"loggedByService": "Conditional Access",
"operationType": "Update",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "60000000-0000-4000-8000-000011101100",
"displayName": "CA001 - Require MFA for all admins",
"type": "Policy",
"userPrincipalName": null,
"groupType": null,
"modifiedProperties": [
{
"displayName": "ConditionalAccessPolicy",
"oldValue": "{\"id\":\"60000000-0000-4000-8000-000011101100\",\"displayName\":\"CA001 - Require MFA for all admins\",\"state\":\"enabled\",\"conditions\":{\"users\":{\"includeRoles\":[\"62e90394-69f5-4237-9190-012177145e10\",\"e8611ab8-c189-46e8-94e1-60213ab1f814\",\"9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3\",\"fe930be7-5e62-47db-91af-98c3a49a38b1\"],\"excludeUsers\":[\"30000000-0000-4000-8000-000000000001\"]},\"applications\":{\"includeApplications\":[\"All\"]}},\"grantControls\":{\"operator\":\"OR\",\"builtInControls\":[\"mfa\"]}}",
"newValue": "{\"id\":\"60000000-0000-4000-8000-000011101100\",\"displayName\":\"CA001 - Require MFA for all admins\",\"state\":\"enabled\",\"conditions\":{\"users\":{\"includeRoles\":[\"62e90394-69f5-4237-9190-012177145e10\",\"e8611ab8-c189-46e8-94e1-60213ab1f814\",\"9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3\",\"fe930be7-5e62-47db-91af-98c3a49a38b1\"],\"excludeUsers\":[\"30000000-0000-4000-8000-000000000001\",\"30000000-0000-4000-8000-001010011010\"]},\"applications\":{\"includeApplications\":[\"All\"]}},\"grantControls\":{\"operator\":\"OR\",\"builtInControls\":[\"mfa\"]}}"
}
]
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1556.009 — Conditional Access Policies — Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts. Conditional access policies are additional verifications used by identity providers and identity and access management systems to determine whether a user should be granted access to...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.