Skip to content

Enhancement: Add support for logging in from managed devices when access policy "block access from apps on unmanaged devices" is active #1979

@mbuergi

Description

@mbuergi

Description

With the SharePoint Admin Center Policy "Block access from apps on unmanaged devices" enabled, users are unable to login to M365 CLI, even when using an ADJoined Device.

Login fails for all federated users.
Login is successful for cloud-only accounts (onmicrosoft accounts).

Steps to reproduce

image

Expected result

Successful sign in with the user provided during the sign-in dialog.

Actual result

Unable to Sign in.
Below the troubleshooting details, in the last line it says "Device State: DomainJoined"

image

When clicking okay, the browser is redirected to: https://login.microsoftonline.com/common/oauth2/nativeclient?error=access_denied&error_subcode=cancel

The logs show, that the conditional access policy created in the first step above blocked the login.

Environment

M365 Version: v3.3.0
OS: Windows 10 Version 1909

We use AD FS, users are authenticated onPrem.

Thanks for lookting into this
Matt

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions