Securing internet traffic from devices with identity-aware web filtering and threat protection
Hello Eben Walker,
Admins can test Conditional Access policies in Report-only mode without enforcing them.
When a policy is set to report only:
- Results are displayed in Sign-in logs → Conditional Access / Report-only. It is evaluated during sign-in but not enforced
- You may track the impact using Conditional Access Insights (Azure Monitor) Therefore, the policy is currently in Report-only mode and NOT enabled.
Reference:
Conditional Access Policy Insights: Monitoring and Evaluation - Microsoft Entra ID | Microsoft
If the resolution was helpful, kindly take a moment to accept the answer and upvote it 👍 it as a token of appreciation.