Sep 30 2019 11:09 AM
Sep 30 2019 11:09 AM
Is there a way to limit the number of devices a user signs into apps protected by app protection policies? We happen to be enforcing MFA in our policies so the devices are appearing in AAD as registered devices.
There are device limits for enrolled devices but enrollment means MDM and we are trying to be as light touch as possible.
The other option appears to be device limits in Azure but I assume that just means all devices including Windows etc and it only allows a figure in increments of 5....
Sep 30 2019 11:30 AM
Sep 30 2019 11:39 AM
I think it is in terms of a reduced attack surface if a user has many devices which could be compromised. I've just been asked if we can do it so am looking into the options.
Sep 30 2019 11:56 AM
Sep 30 2019 11:51 PM
@Deleted There is no such limit for MAM aka azure AD registered devices however for MAM ,you can have app protection policies to secure the data with PIN and store the data only on cloud (onedrive/sharepoint) and lock the app every 5 min of inactivity etc .