Microsoft Entra ID
Conditional Access

Conditional Access Conditions

In brief

The documentation now warns that device platform information, such as user agent strings, can be modified and isn't verified. It recommends using device platform with Microsoft Intune device compliance policies or in a block statement.

What Entra admins need to know

Administrators should consider this limitation when designing Conditional Access policies that use device platform conditions.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Device platforms

Conditional Access identifies the device platform using information provided by the device, such as user agent strings. Because user agent strings can be modified, this information isn't verified. Use device platform with Microsoft Intune device compliance policies or as part of a block statement. By default, it applies to all device platforms.

For agents' user accounts, this condition applies only when the agent session is initiated from an endpoint. Use it with the Agent execution environments condition to avoid targeting agents that run directly in cloud infrastructure.

For agents' user accounts, this condition applies only when the agent session is initiated from an endpoint. Use it with the Agent execution environments condition to avoid targeting agents that run directly in cloud infrastructure.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…