Configure and block SharePoint Online on Unmanaged Devices

Kevin Long Nguyen 20 Reputation points
2024-09-16T04:32:18.3033333+00:00

Hello everyone,

I've configured SharePoint's access control - block unmanaged devices with the following conditional access policies:

Target resources: Office 365 SharePoint Online
Conditions: Client apps - Mobile apps & desktop clients
Grant access: Require device to be marked as compliant
Require Microsoft Entra hybrid joined device

My concern is that I am testing on my IOS device, which has already been registered and compliant with company portal is not allowed to sign-in Teams/SharePoint at all. What am I doing wrong?

User's image

The error while attempting to login was only "An error occurred." on Teams, and within the MS Authenticator it states the following:
User's image

SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
10,827 questions
Microsoft Intune iOS
Microsoft Intune iOS
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.iOS: An Apple mobile operating system.
236 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,202 questions
{count} votes

Accepted answer
  1. Simon Burbery 681 Reputation points
    2024-09-16T05:24:14.81+00:00

    Can you confirm under "Grant" where you selected "Require device to be marked as compliant" and "Require Microsoft Entra hybrid joined device", at the bottom there is a selection for "Require all the selected controls" or "Require one of the selected controls". If that is set to "Require all the selected controls" that would explain the behavior.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.