Microsoft Conditional Access June 2026 Changes: Current Admin Guide

Prepare for baseline-scope enforcement beginning June 15, 2026 and the approved-client-app control becoming read-only on June 30 without misstating continued policy enforcement.

Back to Blog
3 min read
Isometric conceptual timeline diagram showing two Microsoft Entra Conditional Access enforcement deadlines in June 2026

Microsoft published two distinct Conditional Access changes for June 2026. One changes enforcement for baseline scopes in All resources policies with exclusions. The other makes the legacy approved-client-app control and policies that use it read-only while enabled policies continue to enforce.

Current as of 2026-08-15

Microsoft’s baseline-scope guidance says rollout begins June 15, 2026. Microsoft’s migration guidance says the legacy control and policies that include it become read-only June 30, 2026; enabled policies continue enforcing until disabled or deleted.

Decision summary

  • Do not describe June 30 as an automatic shutdown of enabled legacy policies.
  • Inventory All resources policies with exclusions and applications requesting only baseline scopes.
  • Migrate mobile access toward app protection policy controls using report-only validation.
  • Protect emergency access and test application behavior before enforcement changes.

Change one: baseline-scope enforcement

The new model applies Conditional Access evaluation to certain baseline OIDC and directory scopes that previously could bypass enforcement when an All resources policy had resource exclusions. Microsoft says only tenants with the relevant policy and application conditions are affected.

Change two: approved-client-app control

On June 30, administrators lose the ability to create or edit policies that use Require approved client app. Existing enabled policies continue to enforce, and administrators can still disable or delete them. This is a migration deadline for manageability and supportability, not an automatic end to enforcement.

A bounded preparation sequence

  1. Export current Conditional Access policies and identify affected controls and exclusions.
  2. Use sign-in logs and Microsoft’s baseline-scope guidance to identify candidate applications.
  3. Build replacement mobile policies with supported app protection controls.
  4. Start in report-only mode, test representative users and emergency access, then document approval.
  5. Stage production rollout with monitoring and a tested rollback path.

Avoid copy-and-paste policy changes

Tenant roles, applications, device platforms, licensing, and break-glass design vary. Microsoft’s examples are starting points. Validate the exact policy graph and sign-in behavior in the target tenant before changing enforcement.

Next step for your environment

Maintain an evidence packet containing policy exports, affected-app queries, report-only results, approvals, and rollback instructions. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.

Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.

Sources and update trigger

Review trigger: Review throughout Microsoft’s progressive rollout and whenever Microsoft changes the migration or enforcement documentation.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles