Conditional Access Conditions
In brief
The documentation now warns that device platform information, such as user agent strings, can be modified and isn't verified. It recommends using device platform with Microsoft Intune device compliance policies or in a block statement.
What Entra admins need to know
Administrators should consider this limitation when designing Conditional Access policies that use device platform conditions.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Device platforms
Conditional Access identifies the device platform using information provided by the device, such as user agent strings. Because user agent strings can be modified, this information isn't verified. Use device platform with Microsoft Intune device compliance policies or as part of a block statement. By default, it applies to all device platforms.
For agents' user accounts, this condition applies only when the agent session is initiated from an endpoint. Use it with the Agent execution environments condition to avoid targeting agents that run directly in cloud infrastructure.
For agents' user accounts, this condition applies only when the agent session is initiated from an endpoint. Use it with the Agent execution environments condition to avoid targeting agents that run directly in cloud infrastructure.
@@ -57,7 +57,8 @@ When a policy uses this condition, agents that aren't running on a device are ex ## Device platforms -Conditional Access identifies the device platform using information provided by the device, such as user agent strings. Because user agent strings can be modified, this information isn't verified. Use device platform with Microsoft Intune device compliance policies or as part of a block statement. By default, it applies to all device platforms.+> [!WARNING]+> Conditional Access identifies the device platform using information provided by the device, such as user agent strings. Because user agent strings can be modified, this information isn't verified. Use device platform with Microsoft Intune device compliance policies or as part of a block statement. By default, it applies to all device platforms. You should use Conditional Access policies using this condition with another policy (like one requiring device compliance or app protection policies) to mitigate the risk of user agent spoofing. For agents' user accounts, this condition applies only when the agent session is initiated from an endpoint. Use it with the **Agent execution environments** condition to avoid targeting agents that run directly in cloud infrastructure. 