No Conditional Access policy takes precedence over another. Microsoft Entra ID evaluates every policy that applies to a sign-in, and the user has to satisfy all of them. If any applicable policy blocks access, the sign-in is blocked.
That answer surprises people who expect policies to work like firewall rules, where the first match wins. The sections below show how evaluation works, what happens when policies overlap, and how to see which ones applied.
How it works in one minute
- There is no priority order. Policies do not rank against each other, and their position in the list does not matter.
- Every applicable policy is enforced. If one requires MFA and another requires a compliant device, the user needs both.
- Block ends the evaluation. A matching policy with the block control stops enforcement and denies access.
- Report-only policies show their result without enforcing it. They are a safe way to test a change.
How does Entra ID evaluate Conditional Access policies?
Microsoft describes evaluation in two phases. Both run on every sign-in that Conditional Access covers.
Phase 1: collect and match
Entra gathers the details of the sign-in, such as the user, the app, the device platform and the location, then checks which policies match. Enabled and report-only policies are both evaluated here.
Phase 2: enforce
Entra enforces the grant and session controls of every enabled policy that matched. If one of them uses the block control, enforcement stops and the user is blocked.
Within a single policy, every assignment has to match for the policy to apply. A policy scoped to one app and one location applies only when a sign-in includes both.
What happens when two Conditional Access policies apply to the same sign-in?
| Situation | Result |
|---|---|
| Policy A requires MFA. Policy B requires a compliant device. | The user completes MFA and uses a compliant device. |
| Policy A requires MFA. Policy B blocks access. | The user is blocked. Completing MFA does not get around the block. |
| A policy requires all selected controls. | Every control in that policy must be satisfied. This is the default setting. |
| A policy requires one of the selected controls. | Satisfying any one of its controls meets that policy’s requirement. |
| A matching policy is in report-only mode. | The sign-in log records what the policy would have done. It does not change access. |
Because requirements add up, two well-written policies can produce a stricter result than either author intended. That is usually the real problem behind the precedence question.
Is there a tool that shows which Conditional Access policy is taking precedence?
Since no policy outranks another, the useful question is which policies applied to a sign-in and what each one required. Microsoft provides two built-in ways to answer it.
The What If tool
Found under Conditional Access in the Microsoft Entra admin center. You describe a sign-in, and it reports which policies would apply, which would not, and the first condition that ruled each one out. It works for users, agent identities and single tenant service principals.
Sign-in logs
For a sign-in that already happened, the log entry lists each Conditional Access policy and whether it applied, did not apply, or ran in report-only mode. Use it to troubleshoot what a real user experienced.
The What If tool has limits worth knowing. It evaluates only enabled and report-only policies, it does not test service dependencies between apps, and it needs every relevant sign-in detail to evaluate a condition. It also expects individual App IDs, so app groups such as Office 365 do not produce a match.
Why do Conditional Access results drift from what you intended?
Policies are usually right on the day they are written. Over time, exclusions grow, group membership changes, new apps arrive, and an administrator edits one policy without seeing how it combines with the rest.
- Exclusions. Emergency access accounts are a common and reasonable exclusion. Check that every other exclusion still has an owner and a reason.
- Report-only policies left in place. A policy set up for a short test can stay in report-only mode long after the test ends.
- Coverage gaps. Apps, users or sign-in types that no enabled policy covers.
- Untracked edits. Changes made directly in the portal with no record of who changed what.
The Accelerynt Security Platform validates Conditional Access policies for coverage gaps, exclusions and policy drift across your environment. Between the scans your team schedules, drift detection watches critical controls and alerts you when a setting moves from its approved state. It uses read-only permissions.
A Conditional Access gap matters more when it sits next to other weak settings. See how to turn security assessment findings into a remediation roadmap for how to rank fixes, and how to find risky app registrations and service principals in Entra ID for the app side of identity. For drift across the whole tenant, read how to manage Microsoft 365 security and prove it works.
Where to go next
Our Microsoft security engineering team reviews, builds and deploys Conditional Access policies. If you need a control deployed and validated in production, Zero Trust Proof of Progress lists conditional access enforcement among the controls it can deploy. For what happens after a risky sign-in, see automating identity threat response with a Sentinel playbook.
Frequently asked questions
Is there a tool that shows which Conditional Access policy is taking precedence?
Conditional Access has no precedence order, so no tool ranks policies against each other. The What If tool in the Microsoft Entra admin center shows which policies would apply to a sign-in you describe, and the sign-in logs show which policies applied to a real sign-in. Together they show every requirement a user had to meet.
Does a block policy override a grant policy?
Yes. If any enabled policy that applies to the sign-in uses the block control, enforcement stops and the user is blocked, whatever the other matching policies would have allowed.
Are Conditional Access policies processed in order?
No. Entra ID evaluates every matching policy and the user must satisfy all of them. The order policies appear in the admin center has no effect on the result.
What does report-only mode do?
A report-only policy is evaluated at sign-in and its result is recorded in the sign-in logs, without being enforced. Teams use it to see a new policy’s impact before turning it on.
