‹ Back to list
Stay InformedMC1262298

Updates to your Microsoft-Managed Conditional Access policy for risky sign-ins

Services: Microsoft Entra· Published: 2026-03-26· MS modified: 2026-03-26
New featureUser impactAdmin impact

Microsoft announcement

[Introduction]

To strengthen your organization’s security posture, Microsoft is expanding the scope of the Microsoft-managed Risk-Based Conditional Access (RBCA) policy. Beginning in early April 2026, newly identified eligible users in your tenant will automatically be included in the policy to ensure consistent and ongoing protection as your environment evolves.

[When this will happen]

General Availability (Worldwide): The update will begin rolling out in early April 2026.

[How this affects your organization]

Who is affected:

  • Newly identified eligible users within your tenant

What will happen:

  • Newly eligible users will automatically be added to the Microsoft-managed RBCA policy.
  • All users included in the policy will be able to satisfy the controls.
  • No existing Conditional Access settings will be altered.
  • Existing exclusions (such as break-glass accounts) will remain unchanged.
  • The policy will remain enabled by default unless customized.

[What you can do to prepare]

No action is required.

  • Review or customize the policy at Entra Admin Center → Conditional Access → Policies → Microsoft managed.
  • Optional: communicate this update to helpdesk or identity operations teams.
  • If needed, create a support request (Technical → Microsoft Entra Sign-In and Multi Factor Authentication → Conditional Access → Microsoft managed).

Learn more: Microsoft-managed Conditional Access policies | Conditional Access | Microsoft Entra ID | Microsoft Learn

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Change history