Introducing ADAudit Plus' Attack Surface Analyzer—Detect 25+ AD attacks and identify risky Azure configurations. Learn more×
 
Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

 

How to check changes to conditional access policies in Azure

Start your free trial

In Microsoft Entra ID (formerly Azure Active Directory), Conditional Access policies serve as a critical layer of defense that controls user access based on signals such as identity, location, and device compliance. Unauthorized changes to these policies can expose your organization to serious risks. It is essential to monitor who creates, modifies, or deletes these policies to ensure security standards are maintained.

Learn how to track Conditional Access policy activity using Azure’s native auditing capabilities and with ManageEngine ADAudit Plus for deeper visibility and control.

  1. Sign in to the Azure portal

    Go to https://portal.azure.com and log in with a privileged admin account

  2. Open Microsoft Entra ID

    In the left-hand menu of the Azure portal, click All services to browse all available services.

  3. How to check changes to conditional access policies in Azure

    From the list of services, locate and click Microsoft Entra ID.

    How to check changes to conditional access policies in Azure
  4. Navigate to Conditional Access

    After opening Microsoft Entra ID, use the left-hand menu to click Security.

  5. How to check changes to conditional access policies in Azure

    Under Security, click Protect , then select Conditional Access to view policy configurations.

    How to check changes to conditional access policies in Azure
  6. View policies

    In the Conditional Access section, click Policies from the left-hand menu.

  7. How to check changes to conditional access policies in Azure

    Here, you'll see a list of all existing policies, including their name, state (On, Off, Report-only), and timestamps (creation date and modified date).

    How to check changes to conditional access policies in Azure
  8. Inspect policy details

    Select any policy to view its configuration, including the name, assignments, conditions, access controls, session settings, and whether the policy is enabled.

  9. How to check changes to conditional access policies in Azure

    How to audit Conditional Access events in Azure Audit Logs

    1. Open Microsoft Entra ID

      Go to All services > Microsoft Entra ID.

    2. Go to Audit logs

      Click the Monitoring tab on the left, then Audit logs.

    3. How to check changes to conditional access policies in Azure
    4. Filter for Conditional Access change

      Use the Activity filter. Under Value, type "Conditional access" and choose the specific activity you want to audit from the drop-down list.

    5. How to check changes to conditional access policies in Azure
    6. Click on the entry to view details

      Click on any listed entry to open the full details panel. You’ll see information such as activity, date, IP address, etc.

    7. How to check changes to conditional access policies in Azure

    ADAudit Plus, a comprehensive AD auditing tool, helps you audit all changes to your Active Directory, including those performed by administrator accounts.

Steps to audit Conditional Access events using ManageEngine ADAudit Plus

  1. Download and install ADAudit Plus.
  2. Find steps to configure Cloud Directory auditing here .
  3. Open the console, and log in as an administrator.
  4. Navigate to Cloud Directory > Conditional Policy Changes.

Track every addition, update, and deletion to maintain complete oversight of conditional policy changes across your Azure environment:

How to check changes to conditional access policies in Azure

View who created a new Conditional Access policy, along with its time, IP, and user details:

How to check changes to conditional access policies in Azure

Track specific changes made to an existing Conditional Access policy, including the editor and modified attributes:

How to check changes to conditional access policies in Azure

See who deleted a Conditional Access policy and when the deletion occurred for complete change accountability:

How to check changes to conditional access policies in Azure

Advantages of using ADAudit Plus to monitor Conditional Access policies

  • Monitor additions, updates, and deletions of Conditional Access policies in one unified platform.
  • After configuration, retrieve and audit Conditional Access policy changes made up to 30 days prior.
  • View who made each change, when it happened, and the IP address it came from.
  • Get real-time alerts for critical Conditional Access policy modifications.
 

ADAudit Plus Trusted By