The Conditional Access policies you never wrote are already in your tenant
Open the Conditional Access policy list in your tenant and look at the Created by column. If any row says Microsoft, nobody in your company wrote that policy: Microsoft creates it in Report-only and switches it on itself "no less than 30 days" later, with two weeks' notice and a note saying it can be sooner. They cannot be renamed or deleted; the only thing you can change is who you exclude —starting with your emergency account—. Which ten exist today, the three that actually break things (device code flow and Teams rooms, legacy authentication and the scan-to-email printer, MFA for all users and licensed service accounts), the detail almost nobody quotes —your P2 license count and MFA registration draw who the risk policy protects— and the audit query that tells you what Microsoft changed in your tenant and when.