Hey everyone,
I’m stuck with a Conditional access issue and I’m hoping someone here has seen this before.
We have a supervised iOS device enrolled in hexnode, and we’ve also configured the Hexnode Email policy. The device shows as enrolled and compliant in hexnode without any issues.
But when the user tries to sign in to outlook using Microsoft entra credentials, it fails with: “Device unregistered”
What I’m noticing:
- The user is signing in through Edge browser
- The login flow shows the 2FA/MFA prompt
- After the user finishes authentication, it fails and throws the “device unregistered” error
- If we disable Mfa in the policy, outlook login works fine
So, it looks like Conditional access is blocking it, but I don’t get why it says “unregistered” when the device is already compliant in Hexnode.
Anyone know what causes this or what I should check next?