Sep 20 2020
- last edited on
Sep 23 2020
Oct 14 2020 09:56 AM
@Ross Smith IV FYI the demo starting at the 29 min mark has a lot of stuff that was cropped out so you can't see it.
Jan 12 2021 10:34 AM
@Nikolkhaev Yes, when we did the recording there was the expectation APP CA would be supported with Teams in Q4 of 2020. Unfortunately, issues prevented that from happening. We're getting close to releasing support.
Feb 23 2021 10:47 AM - edited Feb 23 2021 11:20 AM
It seems that today, 23 Feb 2021, APP CA support for Teams is still not implemented. What is the best practice to deal with this? Is it having 2 CA's, one for Teams only with "require approved client apps", and one for Office 365 excluding Teams with "require app protection policy"?
I tested, excluding Teams doesn't work - the CA is still activated when accessing Teams. A dependency issue?
The problem is that having just "require approved client apps" for all Office 365 is enough for some of our devices to get APP activated, but for some, not. It needs to be enforced.
Feb 23 2021 03:34 PM
@rupie100 Teams is targeting the end of Q1CY21 to support the Require app protection policy grant access control. In the meantime, you can leverage https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/app-protection-based-cond... to utilize a single policy that supports apps that do and do not support the new grant access control.
Feb 24 2021 01:03 PM
@Ross Smith IV Thank you for the information. I also set it up as you suggested and used the device condition "exclude compliant devices" because I want app protection turned off for managed devices. Now it seems to work.
"Why I didn't do that before is this Microsoft's statement: "Microsoft Teams, Microsoft Kaizala, Microsoft Skype for Business and Microsoft Visio do not support the Require app protection policy grant. If you require these apps to work, please use the Require approved apps grant exclusively. The use of the or clause between the two grants will not work for these three applications."
...which I thought would mean that the APP or managed app should not work for Teams. But it works. Maybe I misunderstood something.