Conditional Access on the Device

For devices that meet the requirements of a compliance policy, accessing resources is seamless. Once a device registers, the user receives access to all authorized resources and applications.

The following example shows a device completing a shared device registration and receiving a device ID.

The following example shows access to Microsoft Teams denied on a registered user device because the device does not meet the requirements of the compliance policy.

When opening a Microsoft 365 application such as Microsoft Teams on an unregistered device, the user must select Authenticate to register it as Microsoft User Mode. Devices configured for Microsoft Shared Mode automatically register to Azure Active Directory.

To register a non-Android Enterprise device as Microsoft Shared Mode, you must unregister and unenroll it from SOTI MobiControl. Re-enroll the device as work managed and register it as Microsoft Shared Mode.

For troubleshooting tips, see the following:

Error On First-time Registration with Azure

Non-compliant devices can access Office 365 apps

Removal of Office 365 Access Not Immediate