Can't request
Can't request closes the door on asking. The people the policy names never see the app or permission in their access catalog, and a direct request for it is refused. Use it when self-service is fine for most of the company but wrong for one group.
What it does
The effect does two things at once, and nothing else:
The target disappears from the access catalog of everyone the policy matches.
A direct request for that target is refused, with a reason.
It grants nothing and it removes nothing. Somebody who already holds the access keeps it, and a Gets policy aimed at the same people still hands it out. If you want the access gone, or blocked outright however it arrives, write a Never gets policy instead.
Write one
Open Managed Access, go to the Policies tab and choose New policy.
Under Who, build the group you want to block. Leave it empty and the sentence reads "Everyone".
Under What, pick the Can't request effect card. A line appears under the picker: "This hides the target from those people's catalog and refuses a direct request."
Choose your targets: individual apps and entitlements, or Everything for an org-wide block.
There is nothing further to set. Can't request offers no approval ladder, no request terms, no enforcement and no manual override setting, because the policy holds no access.
Read the preview column on the right, then choose Create & activate.
When Ploy acts
At the moment somebody asks. A Can't request policy is weighed before any Can request policy, so it wins whenever the two cover the same person and the same target. It beats a full approval ladder and it beats auto approve.
You can see the result on any policy it collides with. Open a Can request policy and look at its Overlapping policies section.
Good to know
It is not a removal. Access people already hold is untouched, and it stays explained by whatever policy explains it today.
Everything is a valid target. Can't request is one of the two refusing effects, and only refusing effects may point at Everything. A Gets policy always has to name something specific.
A Gets policy still grants. People can be assigned access by policy and be unable to ask for it themselves. Ploy treats that as deliberate, not as a conflict.
No enforcement, no manual overrides. Both settings are hidden for the request pair. Nothing to configure means nothing to get wrong.
On-call status is available here. You can select people by whether they are on call, and that field works only on the two request effects, never on Gets or Never gets.
The preview counts decisions, not access. For a Can't request draft, the preview compares what the request gate would answer before and after, so people move between "newly refused" and "already refused" rather than gaining or losing anything.
The drawer has a Requests tab. On a refusing policy it is headed "Requests this policy refused" and lists the requests it turned down.
Disabling or deleting one is safe. Since it holds no access, switching it off provisions nothing and removes nothing. It simply reopens the door.