Entra Conditional Access Policy Issue

Cindy Zhang 20 Reputation points
2025-01-09T04:45:37.3766667+00:00

I am the IT administrator of our company, and for security concerns, I set up one new conditional access policy in Entra, the policy is that our employees' MS accounts can only logged from Intune registered and compliant devices, the policy works well with almost everyone except one user. This user uses Android phone and windows laptop, the issue is with his android phone. He can't use applications which need to login his MS account, and the alerts continue popping up asking him to type in credentials. I checked his sign-in logs and found there were a lot of Gmail login trials, so I excluded Gmail from the policy, and I also excluded his android phone from the policy by adding the phone's Entra device ID. However, he still cannot use the applications and still receives a lot of alerts. The sign-in logs show there are still Gmail login attempts after this user uninstalled Gmail from his phone. That is really weird. I don't know how to fix this issue.

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,409 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,803 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Cindy Zhang 20 Reputation points
    2025-01-09T16:16:06.04+00:00

    The alert popped up and led the user to open 'Company Portal' and type in credentials. 'Company Portal' is the Microsoft application used to register the device.

    That's the weird thing, I added one condition into the policy, if the device ID equals this user's phone's Entra device ID, the device will be excluded from this policy. I don't know why he still received the alerts.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.