Conditional Access stating a Compliant iOS Device is Not-Compliant and blocking sign-in for iOS LastPass App.

Dalton Reeves 121 Reputation points
2023-01-16T22:33:58.1966667+00:00

Sign-In logs show the user is using a non-compliant device, however the device IS compliant.

Sign-in log is also void of the Device ID in this specific log, so it's as if after signing in to the phone app that is SSO'd the deny message says they must use Edge or Safari, but the users are using Safari when they get the message...

	
The user is using a browser that does not support device identification so the device state is unknown. Access to the resource requires a compliant device. To see a list of browsers that support device identification, see https://docs.microsoft.com/azure/active-directory/conditional-access/technical-reference#supported-browsers

Device ID

Browser

Mobile Safari 16.2

Operating System

iOS 16

Compliant

No

Managed

No

Join Type

User's image

UPDATE: As a work around I've removed the Compliant Device requirement for iOS and it works without issue. My assumption is the iOS app is using an embedded Safari browser that for some reason can't play with Conditional Access, however that is a HUGE issue because out LastPass is federated/SSO. Works fine for BYOD Android I might add IF its through the Work Profile.

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
941 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,648 questions
0 comments No comments
{count} votes

9 answers

Sort by: Most helpful
  1. Hamoon Hanifehpour 0 Reputation points
    2023-07-17T10:12:10.8833333+00:00

    have the same Problem with different apps on iPhone:

    Microsoft Teams.

    Microsoft Froms.

    Microsoft Outlook

    device IS compliant but Conditional access says, not it is not.

    User logged in different devices same Problem.

    MFA deleted and logged in again. same problem.

    open Support ticket on Microsoft, and after 100 Meeting, same Problem.

    did someone find a solution?


  2. Panther Fan 0 Reputation points
    2024-05-17T13:12:35.59+00:00

    Did you ever get this resolved, we are seeing the same thing, devices marked as non compliant when trying to sign in via outlook, etc yet the device IS compliant. The grant control just has "require compliant device", nothing special.

    Microsoft seems unable to figure this one out :(

    0 comments No comments

  3. O365-ISS-Admin-BTG 6 Reputation points
    2024-05-27T12:43:14.1866667+00:00

    i don't actually see any answer

    0 comments No comments

  4. O365-ISS-Admin-BTG 6 Reputation points
    2024-05-27T12:45:59.3366667+00:00

    i don't actually see any answersWe have ipads being shown in logs as MAC OS, which we block with Conditional Access.

    Additionally, even though made an exception for compliant devices , the device appears an Unknown

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.