The Conditional Access Policy Existed... But It Wasn't Protecting Anything
The MFA policy was configured.
The risk controls were configured.
Device compliance and named locations were configured.
The dashboard looked healthy.
But the policy was still in Report-only mode.
Microsoft Entra was evaluating sign-ins and recording what would have happened, but it was not actually enforcing the access decision.

Conditional Access Investigation
The policy configuration looked complete. The sign-in logs revealed that the tenant was only simulating protection.
Everything appeared to be configured
The dashboard was telling the truth
- 1
- 2
- 3
- 4
- 5
- 6
Policy state: Report-only Result: reportOnlySuccess Grant control: Require multifactor authentication Enforcement action: None

