Default Conditional Access Policy Not Applied to New Users

Francesco Gatto 20 Reputation points
2025-03-07T21:32:57.7633333+00:00

I have enabled Microsoft's default Conditional Access policy, but I noticed that it is not applied to all users. Specifically, the policy seems to include only users added up to a certain date, while those created afterward are not recognized.

Additionally, when using the "What If" tool, the policy appears as "Excluded" for these new users, even though I haven't manually configured any exclusions.

I also noticed that the "Users and groups" parameter was automatically flagged by the policy, so there shouldn't be any implicit exclusions.

Has anyone else experienced this issue? Is there a way to force the policy to apply to all users, including those created after its activation?

Thanks in advance for your support!

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,603 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.