Teams and Sharepoint apps - Device compliance not working

GonWild 421 Reputation points
2022-09-06T11:27:24.8+00:00

Hello,

For mobile devices, our conditional access rule grants access to all apps if MFA and compliant device is satisfied.

Accessing our web app through Edge (on an enrolled and compliant mobile device), grants access

Accessing the same web app through Teams or Sharepoint app on the same device, denies access.

From the sign in log:
"The requested resource can only be accessed using a compliant device. The user is either using device not managed by a Mobile-Device-Management (MDM) agent like Intune, or it's using an application that doesn't support device authentication."

Can someone confirm this is because device authentication is not supported through these apps, only Edge?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,717 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,331 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jarvis Sun-MSFT 10,091 Reputation points Microsoft Vendor
    2022-09-07T09:33:03.01+00:00

    Hi, @GonWild

    I'm not quite sure what you want Conditional Access to implement or if you can provide more information, such as the Settings interface, apps you have excluded.

    Otherwise, You can try "What if" feature to better understand how policies will affect your users and devices. Please refer to:
    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/what-if-tool
    If there is anything misunderstanding, feel free to let us know.

    Regards,
    Jarvis