Block Personal devices to acces to Desktop apps like teams, Onedrive etc and how to troubleshooting the issue.
You can use Conditional Access to block users based on location, IP address, and more, but now we will talk about blocking access for users who are using personal devices
1. Navigate to Entra ID -> Protection -> Conditional Access and create a new policy.
![]() |
2- Create new policy
3-
- If you assign the policy to all users, be sure to exclude the break-glass account. It's essential to always have a break-glass account in place. In case of an error, you could accidentally lock out all users, so make sure these accounts remain unaffected.
4- In the Target resources select All resources (formerly 'All cloud apps')
5- In the conditions:
- Device platforms: select which devices you want the policy to apply to. In my case i will select windows and MacOS
- Client apps: check all boxes except Browser, which will block everything except the browser.
- Here’s the magic: In the Filter for devices, you can apply these filters:
6- Finally, under Grant, choose Block.
7- Enable the policy and create.
How to troubleshoot if some users fail to sign in? or have som issues?
1- Navigate to Entra ID and then to Users.
2- Choose the user who is having issues with logging in.
3- On the left panel, select Sign-in logs.
4-In the right panel, you should see different options; choose Conditional Access.
You can always check this option if the users have failed to sign in, because the logs provide us with all the information. But keep in mind that the logs may take some time to appear.
Kommentarer
Skicka en kommentar