Why can't "Microsoft-Managed" CA policies be deleted even after turning them off?

Knut Sander Lien Blakkestad 20 Reputation points
2025-04-25T12:46:45.6766667+00:00

Wy can't "Microsoft-Managed" CA policies be deleted after turning them off?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,535 questions
{count} votes

Accepted answer
  1. Sakshi Devkante 3,830 Reputation points Microsoft External Staff Moderator
    2025-04-25T13:34:32.2933333+00:00

    Hello Knut Sander Lien Blakkestad

    Even after you turn off Microsoft-managed Conditional Access (CA) policies, you can’t delete them because:

    These policies are created and controlled by Microsoft to enforce essential security best practices like requiring MFA for admins or blocking legacy auth. Microsoft treats these as foundational, so instead of letting tenants delete them, it allows you to disable them if needed (though it’s not recommended unless you’ve replaced them with your own equivalent policies).

    Entra ID, these policies are flagged as “Microsoft-Managed.” That flag prevents them from being deleted even by Global Admins. It’s sort of like a system file in Windows you can hide it or stop it from running but not delete it outright.

    Regarding this it is mentioned in Microsoft public document: https://learn.microsoft.com/en-us/entra/identity/conditional-access/managed-policies

    User's image

    Microsoft’s current approach leans heavily toward ensuring baseline security That said, feedback like yours does make a difference: Microsoft does listen via channels like the Azure Feedback Portal and UserVoice (where applicable), and they've occasionally adjusted features based on widespread demand. If Microsoft introduces more flexibility in this area in the future, I’ll be happy to help you update your environment accordingly.

    If you feel this clarified your question Please remember to "Accept Answer", so that others in the community facing similar issues can easily find this Post.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.