Conditional Access state in which a policy is evaluated and its outcome logged, but not enforced.
Also called report-only mode.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-500AZ-900SC-900AB-900SC-200SC-300SC-401MD-102
Each book explains Report-only in context, with comparison tables and the common traps.
Terms in this definition
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- State
A parameter in OAuth that carries custom data through the authorisation flow and back, as with the "Support state parameter" option in APIM.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- NOT ENFORCED
Fabric warehouses accept key and uniqueness constraints only with this keyword, so they are recorded for tools like Power BI to use but never validated. Keeping keys correct and unique is therefore the loading process's job.
Related terms
- Conditional Access insights and reporting
Using sign-in data sent to a Log Analytics workspace, this workbook estimates what all your Conditional Access policies, report-only ones included, would do together over a chosen window between 4 hours and 90 days. It needs an Entra ID P1 licence and a role of Security Reader or above.
- Microsoft-managed Conditional Access policies
Policies Microsoft itself adds to qualifying tenants, all named with a Microsoft-managed: prefix. Each starts in report-only mode and is enforced after 30 days or more unless switched Off; you can adjust state and exclusions but not delete or rename them.
- What If tool
Simulates a sign-in to reveal which Conditional Access policies, whether On or Report-only, would take effect.