<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Conditional-Access on IT Admin</title><link>/tags/conditional-access/</link><description>Recent content in Conditional-Access on IT Admin</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 27 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="/tags/conditional-access/index.xml" rel="self" type="application/rss+xml"/><item><title>Conditional Access Guest Accounts</title><link>/posts/post-9/</link><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><guid>/posts/post-9/</guid><description>&lt;p>Guests themselves don&amp;rsquo;t need P1 assigned, but the policy won&amp;rsquo;t do anything until the tenant has P1 active for its own members.&lt;/p>
&lt;p>Enforcement is currently soft, not hard. Microsoft doesn&amp;rsquo;t technically block Conditional Access from working if you&amp;rsquo;re short on licenses — Entra ID processes connections that require multifactor authentication no matter if the account has a premium license — but Microsoft has started surfacing warnings about it: tenants are now seeing informational messages in the Entra admin center flagging that some Conditional Access policies are protecting more users than their current licensing entitlements allow, though this is not a precursor to billing and there&amp;rsquo;s no automated enforcement yet.&lt;/p></description></item></channel></rss>