{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/entra-terms-of-use-acceptance-evidence/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/",
        "slug": "entra-terms-of-use-acceptance-evidence",
        "url": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/entra-terms-of-use-acceptance-evidence/"
        },
        "title": "Treat Entra Terms of Use acceptance as policy evidence—not legal proof",
        "summary": "Microsoft Entra can require interactive acceptance through Conditional Access and report who accepted or declined, but the feature does not determine whether the document or process satisfies a legal obligation.",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:31+00:00",
        "modified_at": "2026-08-25T21:36:17+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 483,
        "potentially_affected": "Organizations using Microsoft Entra Terms of Use for workforce, guest, application, or device-enrollment access.",
        "dse_recommendation": "Define the intended policy purpose with legal and business owners, test interactive sign-in paths, govern document versions, and export acceptance evidence on the required retention schedule.",
        "primary_source": {
            "name": "Set up Microsoft Entra Terms of Use with Conditional Access",
            "url": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> Microsoft Entra Terms of Use can present a PDF during interactive authentication, require acceptance through Conditional Access, and provide acceptance reporting. That is useful access-control and audit evidence. It is not, by itself, a legal conclusion about notice, consent, enforceability, accessibility, or records retention.</p>\n<h2>Source fact: what Microsoft documents</h2>\n<p>Microsoft&#8217;s <a href=\"https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use\" target=\"_blank\" rel=\"noopener noreferrer\">Terms of Use documentation</a> describes uploading a terms document, associating it with Conditional Access, configuring options such as reacceptance and expiration, and reviewing who accepted or declined. Changes to Terms of Use policies are captured in Microsoft Entra audit logs.</p>\n<p>Microsoft distinguishes the Terms of Use report from audit logs. The documentation says acceptance and decline information in the Terms of Use report is stored for the life of the terms, while Entra audit-log retention is separate. It also explains that Terms of Use can only be accepted during interactive authentication. Noninteractive clients and automation therefore require careful scope review. When terms are updated and reacceptance is required, current-version reporting behavior can change.</p>\n<h2>What the source does not establish</h2>\n<p>Microsoft does not state that uploading a document creates an enforceable agreement in every jurisdiction or employment context. The feature does not author the policy, verify that a person read or understood it, establish the correct language or accessible format, or determine how long the organization must preserve evidence. An acceptance record does not prove the user complied with the document afterward.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>What business or legal purpose is the acceptance intended to serve, and who approved the wording?</li>\n<li>Which users, guests, applications, enrollment flows, and cloud resources should receive the prompt?</li>\n<li>Are service accounts, PowerShell, device-code, or other noninteractive paths in scope and able to complete the challenge?</li>\n<li>Which languages, accessibility needs, revision notices, expiration periods, and reacceptance triggers are required?</li>\n<li>How long must the exact document version and acceptance evidence be retained outside short-lived operational logs?</li>\n</ul>\n<h2>DSE recommendation: controlled next steps</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<ol>\n<li>Have policy, HR, privacy, accessibility, and legal owners define the purpose and approve the exact PDF before technical deployment.</li>\n<li>Assign a version identifier and checksum to the document. Record the Conditional Access scope, exclusions, acceptance settings, and effective date.</li>\n<li>Use report-only or a pilot population where available and test interactive browsers, mobile clients, guest access, device enrollment, administrative access, and known automation paths.</li>\n<li>Define what happens when a user declines, cannot interact, needs an accommodation, or requires urgent access.</li>\n<li>Export acceptance evidence and retain it with the corresponding document version under an approved records schedule.</li>\n</ol>\n<h2>Verification and evidence</h2>\n<ul>\n<li>Preserve the approved PDF, checksum, version, publication record, and policy assignment.</li>\n<li>Capture test results for accepted, declined, expired, reacceptance, guest, and excluded scenarios.</li>\n<li>Reconcile the Terms of Use acceptance report with relevant sign-in and audit events.</li>\n<li>Demonstrate that historical evidence remains interpretable after a document revision.</li>\n</ul>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use\" target=\"_blank\" rel=\"noopener noreferrer\">Set up Microsoft Entra Terms of Use with Conditional Access</a> — Microsoft</li>\n</ul>",
        "content_text": "Bottom line: Microsoft Entra Terms of Use can present a PDF during interactive authentication, require acceptance through Conditional Access, and provide acceptance reporting. That is useful access-control and audit evidence. It is not, by itself, a legal conclusion about notice, consent, enforceability, accessibility, or records retention.\nSource fact: what Microsoft documents\nMicrosoft’s Terms of Use documentation describes uploading a terms document, associating it with Conditional Access, configuring options such as reacceptance and expiration, and reviewing who accepted or declined. Changes to Terms of Use policies are captured in Microsoft Entra audit logs.\nMicrosoft distinguishes the Terms of Use report from audit logs. The documentation says acceptance and decline information in the Terms of Use report is stored for the life of the terms, while Entra audit-log retention is separate. It also explains that Terms of Use can only be accepted during interactive authentication. Noninteractive clients and automation therefore require careful scope review. When terms are updated and reacceptance is required, current-version reporting behavior can change.\nWhat the source does not establish\nMicrosoft does not state that uploading a document creates an enforceable agreement in every jurisdiction or employment context. The feature does not author the policy, verify that a person read or understood it, establish the correct language or accessible format, or determine how long the organization must preserve evidence. An acceptance record does not prove the user complied with the document afterward.\nApplicability questions\n\nWhat business or legal purpose is the acceptance intended to serve, and who approved the wording?\nWhich users, guests, applications, enrollment flows, and cloud resources should receive the prompt?\nAre service accounts, PowerShell, device-code, or other noninteractive paths in scope and able to complete the challenge?\nWhich languages, accessibility needs, revision notices, expiration periods, and reacceptance triggers are required?\nHow long must the exact document version and acceptance evidence be retained outside short-lived operational logs?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nHave policy, HR, privacy, accessibility, and legal owners define the purpose and approve the exact PDF before technical deployment.\nAssign a version identifier and checksum to the document. Record the Conditional Access scope, exclusions, acceptance settings, and effective date.\nUse report-only or a pilot population where available and test interactive browsers, mobile clients, guest access, device enrollment, administrative access, and known automation paths.\nDefine what happens when a user declines, cannot interact, needs an accommodation, or requires urgent access.\nExport acceptance evidence and retain it with the corresponding document version under an approved records schedule.\n\nVerification and evidence\n\nPreserve the approved PDF, checksum, version, publication record, and policy assignment.\nCapture test results for accepted, declined, expired, reacceptance, guest, and excluded scenarios.\nReconcile the Terms of Use acceptance report with relevant sign-in and audit events.\nDemonstrate that historical evidence remains interpretable after a document revision.\n\nOfficial references\n\nSet up Microsoft Entra Terms of Use with Conditional Access — Microsoft",
        "content_markdown": "Bottom line: Microsoft Entra Terms of Use can present a PDF during interactive authentication, require acceptance through Conditional Access, and provide acceptance reporting. That is useful access-control and audit evidence. It is not, by itself, a legal conclusion about notice, consent, enforceability, accessibility, or records retention.\n\n## Source fact: what Microsoft documents\n\nMicrosoft’s [Terms of Use documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use) describes uploading a terms document, associating it with Conditional Access, configuring options such as reacceptance and expiration, and reviewing who accepted or declined. Changes to Terms of Use policies are captured in Microsoft Entra audit logs.\n\nMicrosoft distinguishes the Terms of Use report from audit logs. The documentation says acceptance and decline information in the Terms of Use report is stored for the life of the terms, while Entra audit-log retention is separate. It also explains that Terms of Use can only be accepted during interactive authentication. Noninteractive clients and automation therefore require careful scope review. When terms are updated and reacceptance is required, current-version reporting behavior can change.\n\n## What the source does not establish\n\nMicrosoft does not state that uploading a document creates an enforceable agreement in every jurisdiction or employment context. The feature does not author the policy, verify that a person read or understood it, establish the correct language or accessible format, or determine how long the organization must preserve evidence. An acceptance record does not prove the user complied with the document afterward.\n\n## Applicability questions\n\n- What business or legal purpose is the acceptance intended to serve, and who approved the wording?\n\n- Which users, guests, applications, enrollment flows, and cloud resources should receive the prompt?\n\n- Are service accounts, PowerShell, device-code, or other noninteractive paths in scope and able to complete the challenge?\n\n- Which languages, accessibility needs, revision notices, expiration periods, and reacceptance triggers are required?\n\n- How long must the exact document version and acceptance evidence be retained outside short-lived operational logs?\n\n## DSE recommendation: controlled next steps\n\nThe following steps are DSE recommendations based on the cited source.\n\n- Have policy, HR, privacy, accessibility, and legal owners define the purpose and approve the exact PDF before technical deployment.\n\n- Assign a version identifier and checksum to the document. Record the Conditional Access scope, exclusions, acceptance settings, and effective date.\n\n- Use report-only or a pilot population where available and test interactive browsers, mobile clients, guest access, device enrollment, administrative access, and known automation paths.\n\n- Define what happens when a user declines, cannot interact, needs an accommodation, or requires urgent access.\n\n- Export acceptance evidence and retain it with the corresponding document version under an approved records schedule.\n\n## Verification and evidence\n\n- Preserve the approved PDF, checksum, version, publication record, and policy assignment.\n\n- Capture test results for accepted, declined, expired, reacceptance, guest, and excluded scenarios.\n\n- Reconcile the Terms of Use acceptance report with relevant sign-in and audit events.\n\n- Demonstrate that historical evidence remains interpretable after a document revision.\n\n## Official references\n\n- [Set up Microsoft Entra Terms of Use with Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/",
                "url": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Treat Entra Terms of Use acceptance as policy evidence—not legal proof",
                        "item": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/#article",
                "identifier": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/",
                "url": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/",
                "headline": "Treat Entra Terms of Use acceptance as policy evidence—not legal proof",
                "description": "Microsoft Entra can require interactive acceptance through Conditional Access and report who accepted or declined, but the feature does not determine…",
                "abstract": "Microsoft Entra can require interactive acceptance through Conditional Access and report who accepted or declined, but the feature does not determine whether the document or process satisfies a legal obligation.",
                "articleBody": "Bottom line: Microsoft Entra Terms of Use can present a PDF during interactive authentication, require acceptance through Conditional Access, and provide acceptance reporting. That is useful access-control and audit evidence. It is not, by itself, a legal conclusion about notice, consent, enforceability, accessibility, or records retention.\nSource fact: what Microsoft documents\nMicrosoft’s Terms of Use documentation describes uploading a terms document, associating it with Conditional Access, configuring options such as reacceptance and expiration, and reviewing who accepted or declined. Changes to Terms of Use policies are captured in Microsoft Entra audit logs.\nMicrosoft distinguishes the Terms of Use report from audit logs. The documentation says acceptance and decline information in the Terms of Use report is stored for the life of the terms, while Entra audit-log retention is separate. It also explains that Terms of Use can only be accepted during interactive authentication. Noninteractive clients and automation therefore require careful scope review. When terms are updated and reacceptance is required, current-version reporting behavior can change.\nWhat the source does not establish\nMicrosoft does not state that uploading a document creates an enforceable agreement in every jurisdiction or employment context. The feature does not author the policy, verify that a person read or understood it, establish the correct language or accessible format, or determine how long the organization must preserve evidence. An acceptance record does not prove the user complied with the document afterward.\nApplicability questions\n\nWhat business or legal purpose is the acceptance intended to serve, and who approved the wording?\nWhich users, guests, applications, enrollment flows, and cloud resources should receive the prompt?\nAre service accounts, PowerShell, device-code, or other noninteractive paths in scope and able to complete the challenge?\nWhich languages, accessibility needs, revision notices, expiration periods, and reacceptance triggers are required?\nHow long must the exact document version and acceptance evidence be retained outside short-lived operational logs?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nHave policy, HR, privacy, accessibility, and legal owners define the purpose and approve the exact PDF before technical deployment.\nAssign a version identifier and checksum to the document. Record the Conditional Access scope, exclusions, acceptance settings, and effective date.\nUse report-only or a pilot population where available and test interactive browsers, mobile clients, guest access, device enrollment, administrative access, and known automation paths.\nDefine what happens when a user declines, cannot interact, needs an accommodation, or requires urgent access.\nExport acceptance evidence and retain it with the corresponding document version under an approved records schedule.\n\nVerification and evidence\n\nPreserve the approved PDF, checksum, version, publication record, and policy assignment.\nCapture test results for accepted, declined, expired, reacceptance, guest, and excluded scenarios.\nReconcile the Terms of Use acceptance report with relevant sign-in and audit events.\nDemonstrate that historical evidence remains interpretable after a document revision.\n\nOfficial references\n\nSet up Microsoft Entra Terms of Use with Conditional Access — Microsoft",
                "datePublished": "2026-08-25T21:35:31+00:00",
                "dateModified": "2026-08-25T21:36:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Treat Entra Terms of Use acceptance as policy evidence—not legal proof"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Explainer",
                    "Advisory priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 483,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Set up Microsoft Entra Terms of Use with Conditional Access",
                    "url": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use"
                }
            }
        ]
    }
}