Security & Continuity
Conditional Access Troubleshooting
Browse issue-specific guidance for Conditional Access.
- Conditional Access alerts indicate success while end-user experience never changes
- Conditional Access blocks service account unexpectedly
- Conditional Access configuration survives testing but resets after restart or sync
- Conditional Access connector health looks normal but data stops syncing
- Conditional Access credential or certificate rotation breaks an existing integration
- Conditional Access feature works in web app but fails in desktop client
- Conditional Access healthy dashboard status masks a failing production workflow
- Conditional Access logging shows delivery yet the target workflow never completes
- Conditional Access new deployment works for pilot group but not for production rollout
- Conditional Access policy change applies in admin console but target users never receive it
- Conditional Access policy exception fixes one case but similar workflows still fail
- Conditional Access quarantine or protection action triggers but recovery workflow fails
- Conditional Access report-only logs differ from real enforcement outcome
- Conditional Access template duplicated and now two policies conflict
- Conditional Access workflow succeeds for one account but fails for shared or delegated access
- Emergency policy exclusion removed during tenant cleanup
- Guest users can access Teams but blocked from SharePoint
- Legacy app protected by app proxy bypasses expected Conditional Access policy
- Mac browser marked unsupported because device ID claim missing from session
- Named location trusted list updated but browser sessions keep prompting MFA
- New SaaS app blocked because device platform not recognized
- Policy excludes break-glass accounts yet sign-in frequency rule still applies
- Require compliant device policy blocks macOS browser sessions only
- Service account blocked after policy intended only for interactive sign-ins
- Service desk excluded from MFA but registration campaign still interrupts
- Session controls block file download in SharePoint but not in Teams preview
- Session sign in frequency policy causes repeated app prompts
- Terms of use acceptance loops on first login after policy assignment
- Trusted location configured but travel users still blocked
- Trusted network exclusions work for IPv4 but not IPv6 clients