Share via

Question about expected behavior with Conditional Access on iOS and third‑party apps

msamuel 0 Reputation points
2026-02-20T20:18:16.2+00:00

We are trying to understand expected behavior when using Conditional Access on iOS devices.

Environment

Microsoft Entra ID

Microsoft Intune (App Protection Policies – MAM‑WE)

Conditional Access: Require compliant device

iOS devices

Microsoft 365 apps (OneDrive, SharePoint)

Question

On iOS devices protected with Conditional Access and App Protection Policies, we are observing that third‑party applications may be unable to access files stored in SharePoint document libraries, even though the user is already authenticated.

Authentication appears to succeed, and there are no Conditional Access failures shown in Entra sign‑in logs. However, file access from non‑Microsoft apps does not complete successfully.

What we are trying to understand

Is this expected behavior when Conditional Access and device compliance are enforced on iOS?

Are there documented limitations for third‑party mobile applications accessing SharePoint content under these conditions?

Is the recommended approach to access SharePoint files from iOS via Microsoft apps or a browser instead of third‑party apps?

We want to make sure we are designing our mobile workflows in line with supported Microsoft guidance and would appreciate clarification on the intended behavior.

Microsoft Security | Microsoft Entra | Other

1 answer

Sort by: Most helpful
  1. Anonymous
    2026-02-21T00:04:57.85+00:00

    Yes, this is the expected behavior.

    When you enforce Conditional Access (CA) with a "Require compliant device" grant control on iOS, you are effectively creating a boundary that most third-party applications cannot cross. Even if the user is authenticated, the specific technical mechanism used to prove device compliance is rarely supported by non-Microsoft apps.

    Microsoft explicitly states that for a device to be marked as compliant in a CA policy, the app must support broker-assisted authentication.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.