Conditional Access Policy Modified

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Alerts when a Conditional Access policy is updated, which could change access rules and weaken security.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_M365_CONDITIONAL_ACCESS_POLICY_UPDATED" select Action1.CALLER,Action1.TARGET,Action1.RESULT,Action1.OPERATION

Detection

Execution Mode

realtime

Log Sources

Microsoft 365