Policy All Users Device Unknown Unsupported
In brief
The documentation now highlights that device platform conditions rely on user agent strings and recommends pairing them with policies requiring device compliance or app protection to reduce risk.
What Entra admins need to know
Review policies using the device platform condition and consider using them with device compliance or app protection policies.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Users are blocked from accessing company resources when the device type is unknown or unsupported.
[!WARNING]
The device platform condition is based on user agent strings. Conditional Access policies using this condition should be used with another policy, like one requiring device compliance or app protection policies, to mitigate the risk of user agent spoofing.
User exclusions
[!INCLUDE active-directory-policy-exclusions]
@@ -11,7 +11,8 @@ ms.reviewer: lhuangnorth Users are blocked from accessing company resources when the device type is unknown or unsupported. -The [device platform condition](concept-conditional-access-conditions.md#device-platforms) is based on user agent strings. Conditional Access policies using this condition should be used with another policy, like one requiring device compliance or app protection policies, to mitigate the risk of user agent spoofing.+[!WARNING]+> The [device platform condition](concept-conditional-access-conditions.md#device-platforms) is based on user agent strings. Conditional Access policies using this condition should be used with another policy, like one requiring device compliance or app protection policies, to mitigate the risk of user agent spoofing. ## User exclusions [!INCLUDE [active-directory-policy-exclusions](~/includes/entra-policy-exclude-user.md)] 