The Copilot iOS app fails against Conditional Access

Gerry Murphy 40 Reputation points
2024-11-14T17:08:39.14+00:00

Copilot iOS fails against conditional access with a failure reason of : Application does not meet the conditional access approved app requirements.

Application used is not an approved application for conditional access. User needs to use one of the apps from the list of approved applications to use in order to get access. To see a list of approved apps, see https://learn.microsoft.com/entra/identity/conditional-access/concept-conditional-access-conditions#approved-client-app-requirement.

I expected Copilot to be on the list of approved Apps, has anyone else seen this

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
969 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,650 questions
Microsoft Copilot
Microsoft Copilot
Microsoft terminology for a universal copilot interface.
432 questions
0 comments No comments
{count} votes

Accepted answer
  1. Navya 13,965 Reputation points Microsoft Vendor
    2024-11-27T17:49:06.3566667+00:00

    Hi @Gerry Murphy

    I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others ", I'll repost your solution in case you'd like to "Accept " the answer.

    Issue:

    The Copilot iOS app fails against Conditional Access

    Solution:

    Issue resolved by @Gerry Murphy

    MS is moving all of the copilot features into the Office app, so there is no standalone app any longer.

    Sharing an article for reference: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsai The link to turn off Windows copilot is explained towards the bottom of the article.

    The entry point for copilot is now the 365 app. That is what you need to set to the policy around. There are a bunch of changes going with this now https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-data-protection-with-windows-and-microsoft-copilot/4246428

    If I missed anything please let me know and I'd be happy to add it to my answer, or feel free to comment below with any additional information. Thank you again for your time and patience throughout this issue.

    Thanks,

    Navya.

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Navya 13,965 Reputation points Microsoft Vendor
    2024-11-14T23:53:12.8633333+00:00

    Hi @Gerry Murphy

    Thank you for posting this in Microsoft Q&A.

    I understand that you are facing an issue with the Copilot iOS application failing against a Conditional Access policy.

    It appears that the Copilot application is not listed in the approved applications for your organization.

    To see which applications are listed in the approved apps, you can visit this link: https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-grant#require-approved-client-app.

    Your administrator can add Copilot to the list of approved apps so that you can access it without any issues.

    For more information, you can visit this link: https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-approved-app-or-app-protection#require-approved-client-apps-or-app-protection-policy-with-mobile-devices.

    We recommend that administrators put this policy in report-only mode to determine the impact it will have on existing users. Once administrators are comfortable that the policies apply as intended, they can switch to "On" or stage the deployment by adding specific groups and excluding others.

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.