Changes to Conditional Access Policies should not get reported as changes to a Default Policy
Currently, when an admin makes a change to a Conditional Access Policy, changes are also reported for a Default Policy that Administrators have neither visibility nor access to. These changes are shown as being made by a Global Admin., causing confusion and alarms for compliance teams.
If possible, either hide/filter the events in the logs for the Default Policy, or change the user that is making the change to a Microsoft System account.
