T The Triage ManualTechnical Guides for IT Emergencies
P1 · Microsoft 365 & Collaboration

Locked out by Conditional Access

A Conditional Access policy is blocking everyone — including admins. Recover via break-glass, then disable the offending policy, then investigate cause.

Indicators

Likely causes

Diagnostic steps

  1. Use the break-glass / emergency access account — must be excluded from all CA policies, MFA-only with FIDO2 or strong passphrase, monitored separately
  2. Sign in to Entra portal as break-glass admin
  3. Open the offending policy → switch to Report-only mode (do not delete — preserves audit trail)
  4. Verify users can sign in, then investigate via Sign-in logs → Conditional Access tab to confirm which policy blocked
  5. Use 'What If' tool in Entra to model the corrected policy before re-enabling
  6. Document the fix and the policy change in change log

Resolution path

Prevention

Tools

References

microsoft-365entraconditional-accesslockoutbreak-glass