Microsoft managed policies are a different beast with different options and different ways to deal with them.
On the dashboard, there should be a distinction between custom and Msoft Managed ones.
also maybe a way to handle them by automation. For example an option to auto-disable new Microsoft Managed policies that have popped on the tenant, or at the very least some kind of alerting on that