Forum Discussion
Entra Conditional Access Policy not blocking log ins from mobile devices
Hi there.
I've pasted the details below.
I have one user in the 'include' and one user in the 'exclude' to test - we can both access it.
I did revoke sign-in sessions for myself, and was forced to log in everywhere again - but not the powerapps apps on my phone. I'm assuming there is some persistent token on my phone that allows me to stay logged in?
Thanks :)
Amber
Can you share the set of resources included? And can you try without the client app condition?
Revoking sessions should have affected any valid refresh tokens, though it does not invalidate access tokens. If you have the option to test on a different device, this will tell us for sure whether something "cached" is causing this behavior.
- AmberH675Sep 29, 2026Tin Contributor
FYI - I did try to access on another device, with my same credentials.
I get the "You cannot access this right now". The only option is to cancel. So I am blocked.
The difference on my cell (and the few others that it IS working on) is that there is an OK button, press it, the message shows up one more time, press it again - I'm allowed to use PowerApps.
How can I clear any caches, tokens, etc.?
A
- AmberH675Sep 29, 2026Tin Contributor
Hi there,
Thanks for your help.
I've shared the resources and also the 'condition' - which is the mobile OS list.
I'm not sure what the client app condition is? I see on the screen I shared above Client apps - 1 included - but when I edit the policy, I don't see client apps anywhere, except in the screen I pasted below - and it says 'not configured'.I've pasted the session options as well - should I be using any of these?
In the meantime I will test on a phone that has never access the PowerApps apps before.
Amber- VasilMichevSep 29, 2026MVP
Hm, how did you create this policy? Usually when we have "hidden" conditions, those correspond to controls that are not currently exposed via the UI, as in the policy was provisioned via the Graph API.
In any case, based on your latest tests, the policy does seem to work as expected, and we need to figure out how to clear the cached credentials/tokens. There should be a "Clear cache" button in the app, under User profile - see if hitting it makes a difference. Or as a last resort, consider reinstalling it.
- AmberH675Sep 30, 2026Tin Contributor
Hi,
I created the policy through Entra - conditional access - policies -> add policy.
My problem is that this app has been in use for some time. I have users on their personal phones, accessing the app from home. I want to block this. It seems surprising to me that revoking all sessions doesn't force a log out of the app - and then allow the policy to block further access.