Configure Entra ID conditional access
- Depending on the email client that your organization wants to use, you must complete additional steps to ensure that the mail client can validate and communicate with Entra:
- For BlackBerry Work, see Configuring the BlackBerry Work app configuration for Entra ID conditional access in the BlackBerry Work Administration Guide.
- For the iOS native mail client, see KB 94163.
- For Android Gmail, see KB 94494.
- After a user activates a device with UEM, you can check the user's device properties in Microsoft Endpoint Manager to confirm that it was registered with Entra as expected. The name of the device will be in the following format: <username> - <platform> unknown unknown - <xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx>.
- If you change the scope of users or groups in the Entra partner compliance configuration, in the Entra portal, navigate to the security permissions for BlackBerry UEM Conditional Access and grant administrator consent for BlackBerry again.
- When you remove a device from UEM, the device remains registered for Entra ID conditional access. Users can remove their Entra ID account from the account settings in the Microsoft Authenticator app, or you can remove the device from the Entra portal.