SOLVED

CA policy Chrome browser iphone

Iron Contributor

Hello

I have a user that is getting a failed login because non supported browser. The user is using iPhone iOS 14.6 and chrome browser  version "Chrome Mobile iOS 92.0.4515". The user is trying to access exchange online application.  When i look at the azure sign-in logs for the request. I see "530001 browser not supported".  I can also see from looking at the sign-in logs that MFA was successfully completed. When i click on "Conditional Access" I see a policy that is reporting as "Failure", and its "Grant Controls" that is not being satisfied .  The policy is configured as below. I'm a little stumped on why "Grant Controls" is not being satisfied when the device is compliant, and the user is successfully passing mfa

 

Skipster3111_0-1627490564208.png

Skipster3111_1-1627490593875.png

Skipster3111_2-1627490631051.png

 

 

 

2 Replies
best response confirmed by Skipster311-1 (Iron Contributor)
Solution
When device state is one of the controls put in place, you need to use a supported browser to be able to satisfy this control. Chrome on iOS is not supported, have a look at the URL below. The only supported browsers on iOS are Edge, Intune Managed Browser or Safari.

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-acces...
Thank you
1 best response

Accepted Solutions
best response confirmed by Skipster311-1 (Iron Contributor)
Solution
When device state is one of the controls put in place, you need to use a supported browser to be able to satisfy this control. Chrome on iOS is not supported, have a look at the URL below. The only supported browsers on iOS are Edge, Intune Managed Browser or Safari.

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-acces...

View solution in original post