Skip to main content

microsoft.conditionalAccess.policy.conditions.users

Description

Users, groups, and roles included in and excluded from a Microsoft Entra Conditional Access policy scope

Fields

IDTYPEDESCRIPTION
includeUsers[]stringUser IDs in scope of policy unless explicitly excluded, None, All, or GuestsOrExternalUsers
excludeUsers[]stringUser IDs excluded from scope of policy and/or GuestsOrExternalUsers
includeGroups[]stringGroup IDs in scope of policy unless explicitly excluded
excludeGroups[]stringGroup IDs excluded from scope of policy
includeRoles[]stringRole IDs in scope of policy unless explicitly excluded
excludeRoles[]stringRole IDs excluded from scope of policy