Managed devices being detected as unmanaged in Access policy
I have an Access policy that targets devices that are not hybrid AD joined to block the OneDrive client syncing on personal devices. This is tested and working, but i’m finding that 1 of my pilot managed devices is intermittently displaying the cloud apps popup when OneDrive is being accessed.
The device in question is a corporate laptop running Windows 11 with a join type of “Microsoft Entra joined”.
When I look at the logs all OneDrive activities are allowed except for the ones with a description of “open in native app” which are being blocked, these have an activity type of “Download File”. Under User Agent Tag it only shows Intune Compliant, although I am not targeting this in the Access policy. I’ve noticed many computers in Entra ID are showing as non-compliant and didnt initially want to restrict them so did not tick it, should I?
Given a fleet of 17,000 devices, I need to understand why we are getting false positives and fix it before I roll out the policy to all of them. Any help is appreciated.
Thanks.
I have an Access policy that targets devices that are not hybrid AD joined to block the OneDrive client syncing on personal devices. This is tested and working, but i’m finding that 1 of my pilot managed devices is intermittently displaying the cloud apps popup when OneDrive is being accessed. The device in question is a corporate laptop running Windows 11 with a join type of “Microsoft Entra joined”. When I look at the logs all OneDrive activities are allowed except for the ones with a description of “open in native app” which are being blocked, these have an activity type of “Download File”. Under User Agent Tag it only shows Intune Compliant, although I am not targeting this in the Access policy. I’ve noticed many computers in Entra ID are showing as non-compliant and didnt initially want to restrict them so did not tick it, should I? Given a fleet of 17,000 devices, I need to understand why we are getting false positives and fix it before I roll out the policy to all of them. Any help is appreciated. Thanks. Read More