Forum Discussion
bart_vermeersch
Nov 06, 2021Iron Contributor
Activity details: Sign ins tab contains very old and already deleted conditional access policies??
We're a but surprised (and worried) to see very old conditional access policies, which were deleted months ago, resurface on the Sign ins tab in the sign in logs of AAD.
By accident we stumbled upon a few user sign in logs with references too non-exiting conditional access policies. On the pane below, we see 30 policies listed for these sign ins while we currently have less than 10 conditional access policies. Most sign in are ok and just list the existing policies.
Anyone else seen this weird and worrisome behavior?
2 Replies
- Can't say I've ever seen deleted policies resurface, but there were some changes recently that caused older "classic" policies to be exposed in the UI. In any case, best check with support.
- bart_vermeerschIron ContributorAccording to Support it is related to the new resilience defaults (which are in preview and already enabled by default). A bit odd that a backup IAM seem to have very old CA policies.
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/resilience-defaults