Conditional Policy not matching Platform and blocking access

KalpAdmin 0 Reputation points
2024-10-28T18:49:17.2433333+00:00

We are implementing a conditional access policy to limit BYOD iPhones to use the Outlook App.

We have followed the recommendations in

https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-approved-app-or-app-protection#configuration

The conditional access policy included IOS and Android only and added the recommended Application Protection Policy

Looking at he report-only sign in logs for our test user we see that the policy is blocked because the platform is not matched

====================================================

User's image

======================================================

The conditional Policy has this

================================================

User's image

====================================================

Can anyone tell me why the platform is showing as "not matched" in the report?

Thanks

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,932 questions
Microsoft Entra
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 149.7K Reputation points MVP
    2024-10-28T18:56:47.1366667+00:00

  2. Xenia-MSFT 2,825 Reputation points Microsoft Vendor
    2024-10-29T05:43:44.07+00:00

    @KalpAdmin Thanks for posting in our Q&A.

    From the screen shot you provide, it shows "platform excluded", please check if you exclude "iOS" under Conditions > Device platforms > Exclude in this conditional access policy.

    If there is anything update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.