I am the IT administrator of our company, and for security concerns, I set up one new conditional access policy in Entra, the policy is that our employees' MS accounts can only logged from Intune registered and compliant devices, the policy works well with almost everyone except one user. This user uses Android phone and windows laptop, the issue is with his android phone. He can't use applications which need to login his MS account, and the alerts continue popping up asking him to type in credentials. I checked his sign-in logs and found there were a lot of Gmail login trials, so I excluded Gmail from the policy, and I also excluded his android phone from the policy by adding the phone's Entra device ID. However, he still cannot use the applications and still receives a lot of alerts. The sign-in logs show there are still Gmail login attempts after this user uninstalled Gmail from his phone. That is really weird. I don't know how to fix this issue.