A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To exclude the Microsoft Authenticator app from a Conditional Access Policy (CAP) that blocks all resources on personal devices, you can create an exclusion specifically for the Authenticator app. Here are the general steps to do this:
- Access the Microsoft Entra admin center: Sign in as a Conditional Access Administrator.
- Navigate to Conditional Access Policies: Go to Entra ID > Conditional Access > Policies.
- Edit your existing policy: Find the policy that blocks access on personal devices and select it for editing.
- Add an exclusion: Under the Assignments section, look for the Cloud apps or actions option. Here, you can specify the Microsoft Authenticator app to be excluded from the policy.
- Save your changes: After making the necessary adjustments, ensure you save the policy.
By following these steps, you should be able to allow access to the Microsoft Authenticator app while still enforcing restrictions on other resources on personal devices.
References: