Conditional Access What If Tool - Not Enough Information

Lavanya Roy 61 Reputation points
2022-04-18T16:13:13.443+00:00

I currently have two policies in place in conditional access:

  • MFA required for all user regardless of location/no conditions/ all cloud apps
  • Block user access if country is any other than US-Mexico-Canada

When I run the What If tool, for a user, for an IP address located in US, under the policies that will apply, it only shows the Block user policy
Under the policies that will not be applied, I can see the MFA requirement policy, saying not enough information.

By my understanding, both should be visible? Am I right? if so is there any reason why that is happening?

Thanks

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,459 questions
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,306 Reputation points
    2022-04-19T07:53:23.643+00:00

    Hi @Lavanya Roy • Thank you for reaching out.

    When there are multiple CA policies in place with conflicting conditions, all the policies are evaluated but the most restrictive one gets applied. In your case, the first policy grants access to all users after they perform MFA, and the second policy blocks access for users from the specified countries. When users from the US try to sign in, they will be within the scope of both the policies, and after evaluating both the policies, the most restrictive one gets applied.

    Ideally, the WhatIf tool should show both the policies but I've seen "not enough information" is returned when the tool is not able to map the conditions to the policies and requires you to relax the conditions. For the policies with "not enough information", try running the query without IP and country.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful