# Treat Entra Terms of Use acceptance as policy evidence—not legal proof

> Microsoft Entra can require interactive acceptance through Conditional Access and report who accepted or declined, but the feature does not determine whether the document or process satisfies a legal obligation.

- Canonical URL: https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-25T21:35:31+00:00
- Modified: 2026-08-25T21:36:17+00:00
- Last reviewed by DSE: 2026-08-25
- Resource type: Explainer
- DSE priority: Advisory
- Topics: Cybersecurity, Microsoft 365 & Identity
- Reading time: 3 minutes

## What you need to know

Microsoft Entra can require interactive acceptance through Conditional Access and report who accepted or declined, but the feature does not determine whether the document or process satisfies a legal obligation.

## Potentially affected

Organizations using Microsoft Entra Terms of Use for workforce, guest, application, or device-enrollment access.

## DSE recommendation

Define the intended policy purpose with legal and business owners, test interactive sign-in paths, govern document versions, and export acceptance evidence on the required retention schedule.

## Article

Bottom line: Microsoft Entra Terms of Use can present a PDF during interactive authentication, require acceptance through Conditional Access, and provide acceptance reporting. That is useful access-control and audit evidence. It is not, by itself, a legal conclusion about notice, consent, enforceability, accessibility, or records retention.

## Source fact: what Microsoft documents

Microsoft’s [Terms of Use documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use) describes uploading a terms document, associating it with Conditional Access, configuring options such as reacceptance and expiration, and reviewing who accepted or declined. Changes to Terms of Use policies are captured in Microsoft Entra audit logs.

Microsoft distinguishes the Terms of Use report from audit logs. The documentation says acceptance and decline information in the Terms of Use report is stored for the life of the terms, while Entra audit-log retention is separate. It also explains that Terms of Use can only be accepted during interactive authentication. Noninteractive clients and automation therefore require careful scope review. When terms are updated and reacceptance is required, current-version reporting behavior can change.

## What the source does not establish

Microsoft does not state that uploading a document creates an enforceable agreement in every jurisdiction or employment context. The feature does not author the policy, verify that a person read or understood it, establish the correct language or accessible format, or determine how long the organization must preserve evidence. An acceptance record does not prove the user complied with the document afterward.

## Applicability questions

- What business or legal purpose is the acceptance intended to serve, and who approved the wording?

- Which users, guests, applications, enrollment flows, and cloud resources should receive the prompt?

- Are service accounts, PowerShell, device-code, or other noninteractive paths in scope and able to complete the challenge?

- Which languages, accessibility needs, revision notices, expiration periods, and reacceptance triggers are required?

- How long must the exact document version and acceptance evidence be retained outside short-lived operational logs?

## DSE recommendation: controlled next steps

The following steps are DSE recommendations based on the cited source.

- Have policy, HR, privacy, accessibility, and legal owners define the purpose and approve the exact PDF before technical deployment.

- Assign a version identifier and checksum to the document. Record the Conditional Access scope, exclusions, acceptance settings, and effective date.

- Use report-only or a pilot population where available and test interactive browsers, mobile clients, guest access, device enrollment, administrative access, and known automation paths.

- Define what happens when a user declines, cannot interact, needs an accommodation, or requires urgent access.

- Export acceptance evidence and retain it with the corresponding document version under an approved records schedule.

## Verification and evidence

- Preserve the approved PDF, checksum, version, publication record, and policy assignment.

- Capture test results for accepted, declined, expired, reacceptance, guest, and excluded scenarios.

- Reconcile the Terms of Use acceptance report with relevant sign-in and audit events.

- Demonstrate that historical evidence remains interpretable after a document revision.

## Official references

- [Set up Microsoft Entra Terms of Use with Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use) — Microsoft

## Primary reference

- Name: Set up Microsoft Entra Terms of Use with Conditional Access
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/entra/identity/conditional-access/terms-of-use
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat Entra Terms of Use acceptance as policy evidence—not legal proof,” DSE Security, https://update.dsesecurity.com/updates/entra-terms-of-use-acceptance-evidence/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
