Share via

How do you edit the Microsoft Managed Conditional Access Policies?

Matthew Castaldo 0 Reputation points
2025-11-24T21:11:26.6866667+00:00

Hello,

I am trying to edit one of the Microsoft Managed Policies under my Conditional Access Policies. I have the roles of Global Administrator and Conditional Access Administrator.

I am trying to exclude a user from a policy. When I exclude the user and save the policy, I get an error saving since "there are no users or groups selected". The issue is, I do not have permissions to selecte any users or groups (see attachment). This leads me to being unable to edit the policy and is causing a ton of issues.

I reached out to Microsoft Entra support OVER TWO WEEKS AGO and still have not heard anything back.

Does anyone have any suggestions?

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Adam Zachary 2,265 Reputation points
    2025-11-25T03:25:51.15+00:00

    You cannot edit Microsoft-managed Conditional Access policies the same way you edit your own custom policies. Even with Global Administrator and Conditional Access Administrator, Microsoft-managed policies have locked scopes. That is why the “Users and groups” section is disabled and why saving fails when you try to exclude someone.

    To adjust them, you only have two supported options:

    Turn the Microsoft-managed policy off.

    Create your own custom Conditional Access policy that replaces it, where you control the assignments and exclusions.

    You cannot change the user or group assignments inside a Microsoft-managed CA policy.

    The UI is locked by design, so the error you see is expected behavior and not a permissions issue.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.