By default, Microsoft Conditional Access policies affect all cloud applications created in your Entra ID portal. If you no longer need the Microsoft Conditional Access policy applied to your Jamf Connect application, the scope can be modified to exclude the application. Changing the scope removes the existing Conditional Access policy and allows for a new configuration to be set up.
- In the Microsoft Entra ID portal, navigate to Entra ID Conditional Access.
- Examine any Conditional Access policies applied to the scope of All cloud apps. Determine if any of the policies have been granted Allow access to the following controls:
Require multifactor authentication
Require authentication strength
Require device to be marked as compliant
Require Hybrid Entra ID joined device
Require any custom rules to include a third party authentication method like Duo
- Click Cloud apps or actions.
- Click the Exclude tab, then select the Custom Security Attribute for your Jamf Connect application.
Existing Conditional Access policies will no longer be applied to your Jamf Connect application and a new configuration can be set up.