I cannot seem to get application based conditional access working at all. We have a third-party application provider that has Microsoft Authentication enabled and this appears in our Azure AD under Enterprise Applications.
I have setup a basic Conditional Access Policy with the following settings:
User/Groups: Single test user
Cloud Apps or Actions: This one app
Access Controls: Block Access
When I try and log in as this user access is granted. Things that make me think it is setup as it should be and is possibly a bug:
- Under Azure AD logs the correct Application Name and ID is displayed
- Under the Enterprise Application window I can see all the successful logins indicating the App is correctly linked
- Running the 'What If' seems to suggest the conditions should be met
- No other access policies are configured for this user to conflict with
When I look at the Conditional Access details under the log, however, it states Application: Not Satisfied. Any ideas where I could be going wrong or how I get in touch with MS to rectify.