What you need to know
Microsoft Entra can require interactive acceptance through Conditional Access and report who accepted or declined, but the feature does not determine whether the document or process satisfies a legal obligation.
Potentially affected
Organizations using Microsoft Entra Terms of Use for workforce, guest, application, or device-enrollment access.
DSE recommendation
Define the intended policy purpose with legal and business owners, test interactive sign-in paths, govern document versions, and export acceptance evidence on the required retention schedule.
Bottom line: Microsoft Entra Terms of Use can present a PDF during interactive authentication, require acceptance through Conditional Access, and provide acceptance reporting. That is useful access-control and audit evidence. It is not, by itself, a legal conclusion about notice, consent, enforceability, accessibility, or records retention.
Source fact: what Microsoft documents
Microsoft’s Terms of Use documentation describes uploading a terms document, associating it with Conditional Access, configuring options such as reacceptance and expiration, and reviewing who accepted or declined. Changes to Terms of Use policies are captured in Microsoft Entra audit logs.
Microsoft distinguishes the Terms of Use report from audit logs. The documentation says acceptance and decline information in the Terms of Use report is stored for the life of the terms, while Entra audit-log retention is separate. It also explains that Terms of Use can only be accepted during interactive authentication. Noninteractive clients and automation therefore require careful scope review. When terms are updated and reacceptance is required, current-version reporting behavior can change.
What the source does not establish
Microsoft does not state that uploading a document creates an enforceable agreement in every jurisdiction or employment context. The feature does not author the policy, verify that a person read or understood it, establish the correct language or accessible format, or determine how long the organization must preserve evidence. An acceptance record does not prove the user complied with the document afterward.
Applicability questions
- What business or legal purpose is the acceptance intended to serve, and who approved the wording?
- Which users, guests, applications, enrollment flows, and cloud resources should receive the prompt?
- Are service accounts, PowerShell, device-code, or other noninteractive paths in scope and able to complete the challenge?
- Which languages, accessibility needs, revision notices, expiration periods, and reacceptance triggers are required?
- How long must the exact document version and acceptance evidence be retained outside short-lived operational logs?
DSE recommendation: controlled next steps
The following steps are DSE recommendations based on the cited source.
- Have policy, HR, privacy, accessibility, and legal owners define the purpose and approve the exact PDF before technical deployment.
- Assign a version identifier and checksum to the document. Record the Conditional Access scope, exclusions, acceptance settings, and effective date.
- Use report-only or a pilot population where available and test interactive browsers, mobile clients, guest access, device enrollment, administrative access, and known automation paths.
- Define what happens when a user declines, cannot interact, needs an accommodation, or requires urgent access.
- Export acceptance evidence and retain it with the corresponding document version under an approved records schedule.
Verification and evidence
- Preserve the approved PDF, checksum, version, publication record, and policy assignment.
- Capture test results for accepted, declined, expired, reacceptance, guest, and excluded scenarios.
- Reconcile the Terms of Use acceptance report with relevant sign-in and audit events.
- Demonstrate that historical evidence remains interpretable after a document revision.
Official references
Review the official source
Set up Microsoft Entra Terms of Use with Conditional Access · Verified August 25, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE