
Conditional Access Enforcement Gap: The OIDC Sign-In Bypass Microsoft Just Closed
Microsoft Entra ID was silently skipping Conditional Access policy evaluation for OIDC-scope sign-ins when resource exclusions were present. As of June 15, 2026, enforcement has changed. Tenants need to audit CA policies and test affected apps now.
15-30 Minutes (with Overe)