Microsoft-managed CA policy update: Expanding user coverage for Risk-Based Conditional Access
Microsoft announcement
To strengthen your organization’s security posture, Microsoft is expanding the scope of the Microsoft-managed Risk-Based Conditional Access (RBCA) policy. Beginning in Early June 2026, newly identified eligible users in your tenant will automatically be included in the policy to ensure consistent and ongoing protection as your environment evolves.
[When this will happen]
General Availability (Worldwide): The update will begin rolling out in Early June 2026.
[How this affects your organization]
Who is affected:
- Newly identified eligible users within your tenant
What will happen:
- Newly eligible users will automatically be added to the Microsoft-managed RBCA policy.
- All users included in the policy will be able to satisfy the controls.
- No existing Conditional Access settings will be altered.
- Existing exclusions (such as break-glass accounts) will remain unchanged.
- The policy will remain enabled by default unless customized.
[What you can do to prepare]
- No action is required.
- Review or customize the policy at Entra Admin Center → Conditional Access → Policies → Microsoft managed.
- Optional: communicate this update to helpdesk or identity operations teams.
- If needed, create a support request (Technical → Microsoft Entra Sign-In and Multi Factor Authentication → Conditional Access → Microsoft managed).
Learn more:
[Compliance considerations]
No compliance considerations identified. Review as appropriate for your organization.
Change history
- 2026-07-31 · Created · All