azure-docs
azure-docs copied to clipboard
Why are Global Administrators not included?
I do not really follow why we are excluding all Global Admins in setting up this policy. I would say it is critical that you enable this especially for Global Admins. I get that you might want to exclude GA's initially to prevent locking oneself out, but then make a note on this, don't simply say "exclude GA's". Would be curious to hear the reasoning on why it is stated that way and would recommend a change there. Hope the feedback helps :)
Document Details
⚠ Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.
- ID: d8685f6c-3ff4-47ba-454d-241ff3abc590
- Version Independent ID: 76de1516-981d-1fd3-efc9-de7908621e5b
- Content: Control security information registration with Conditional Access - Azure Active Directory - Microsoft Entra
- Content Source: articles/active-directory/conditional-access/howto-conditional-access-policy-registration.md
- Service: active-directory
- Sub-service: conditional-access
- GitHub Login: @MicrosoftGuyJFlo
- Microsoft Alias: joflore
@jotheman0303 Thanks for your feedback! We will investigate and update as appropriate.
Hi @jotheman0303
Thank you for your feedback. I understand your concern. The reason for excluding Global Admins in the initial setup of a Conditional Access policy is to prevent administrators from locking themselves out of their directory. If a policy is applied to all users and all apps, it can result in administrators being unable to access their directory.
To avoid this situation, it is recommended to apply the policy to a small set of users first to verify that it behaves as expected. Additionally, it is recommended to exclude at least one administrator from the policy to ensure that there is still access to the policy in case changes are required.
I agree with your suggestion to make a note on this and provide more context on why Global Admins are excluded in the initial setup. I will pass this feedback along to the appropriate team for consideration.
Let me know if you have any other questions or concerns.
For you information Please refer the below in documented link
https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-users-groups https://learn.microsoft.com/en-us/azure/active-directory/governance/conditional-access-exclusion
@MicrosoftGuyJFlo Can you please check and add your comments on this doc update request as applicable.
Will look at this with the Product Group when updating the doc in the future. Thanks for the feedback #please-close