Elevate Your Egnyte Expertise. Join our Customer Community to connect with a network of peers and share game-changing strategies. Join Today

Welcome to
Help Desk

Product Updates
Training
Support
Ideas Community Contact Support

Conditional Access in the Egnyte for Intune iOS App

This article describes functionality that will be available in version 9.9 of the Egnyte for Intune iOS app. Version 9.9 is expected to be available in the Apple App Store on August 5, 2026, when the rollout will begin. This article has been published in advance to allow administrators and users to prepare for the upcoming changes.

Starting with version 9.9 of the Egnyte for Intune iOS app, Conditional Access policies configured in Microsoft Entra ID are enforced both during sign-in and while the app is in active use. This article explains how Conditional Access works in the app, what users may experience, and what IT administrators can do to manage access.

Skip Ahead To...

What is Conditional Access?

When Conditional Access is Evaluated?

What Users See When Conditional Access Blocks Access

Impact Scenarios for IT Administrators

Admin Guidance: Managing Conditional Access Policies

Additional Information

 

What is Conditional Access?

Conditional Access is a Microsoft Entra ID feature that allows IT administrators to define rules governing when and how users can access organizational applications. These rules, called Conditional Access policies, can require that a user's device is enrolled and compliant with company policies, that certain authentication apps are installed, or that sign-in comes from a specific network or location. For a full overview, see Microsoft's Conditional Access documentation.

When Conditional Access is Evaluated?

In version 9.9 and higher for the Egnyte iOS for Intune Mobile App, Conditional Access policies are evaluated at two points:

At Sign-In

When a user signs in to the app for the first time, Microsoft's authentication component (MSAL) checks whether any Conditional Access policies apply to the user. If a policy is in place and the user or device does not meet its requirements, sign-in is blocked before it completes. The user sees a message from Microsoft explaining what is required.
Intune_Conditional Access1.png

When Returning to the App from the Background

Each time the app is brought back to the foreground from the background, the app silently verifies that the user's access is still permitted under current Conditional Access policies. This check happens automatically, with no action required from the user under normal circumstances. If an IT administrator changes a Conditional Access policy after a user has already signed in, for example, by adding a device compliance requirement, the next time that user opens the app from the background, the check will fail and the app will display an alert.
Intune_Conditional Access2.png

Back to Top ↑

What Users See When Conditional Access Blocks Access

During Sign-In

If a Conditional Access policy blocks a user at sign-in, a message from Microsoft is displayed. The most common messages and their meaning are:

  • Message "Install Microsoft Authenticator": The organization's Conditional Access policy requires the Microsoft Authenticator app to be present on the device. The user should install Microsoft Authenticator from the App Store and then attempt to sign in again
  • Message "Secure this device before you can access Egnyte" or "Your device needs to be managed": The organization's Conditional Access policy requires the device to be enrolled and managed through Microsoft Intune. The user should install the Microsoft Intune Company Portal app and enroll the device. If the user is unsure how to enroll, they should contact their IT administrator. For reference, Microsoft's enrollment guidance for iOS devices is available at Microsoft websites.

If after taking the appropriate steps the user is still blocked, they should contact their IT administrator, as the policy configuration may require changes.

During Active App Use

If a Conditional Access policy change causes a check to fail when the app is returned from the background, a notification is displayed within the app with two options:

  • Sign In Again: the user is taken through the Microsoft authentication step. If the Conditional Access requirement can be satisfied (for example, by authenticating via Microsoft Authenticator), sign-in completes and the user can continue using the app.
  • Remove Account: the user's account is removed from the app and they are signed out. The next time the app is opened, the full sign-in flow is required.

If the user closes the notification without selecting an option, it will reappear the next time the app is brought to the foreground.

Back to Top ↑

Impact Scenarios for IT Administrators

IT administrators should review their organization's Conditional Access policies before users update to version 9.9 The following scenarios describe how different users may be affected.

  • Scenario 1: Users with no Conditional Access policies assigned
    Users who are not subject to any Conditional Access policies in Microsoft Entra ID are not affected. They can continue using the app without any change to their experience.
     
  • Scenario 2: Users already signed in, Conditional Access policies assigned but previously not affecting active sessions
    Users who are already signed in will not be signed out when they update the app. However, the next time they bring the app to the foreground after updating, the app will check whether current Conditional Access policies permit access. If a policy requires device compliance and the device is not compliant, the in-app alert described above will be displayed.
    • Admin Action: Before the release, administrators should review all Conditional Access policies that apply to Egnyte for Intune iOS app users and ensure that the policies reflect the intended scope. Users who are not intended to be subject to a given policy should be excluded from it before the update reaches them.
       
  • Scenario 3: Users signing in for the first time after updating, no blocking policies
    New users or users signing in for the first time are guided through the updated sign-in flow. If no Conditional Access policies block them, the flow completes normally. See Signing in to the Egnyte for Intune iOS App for a step-by-step description.
     
  • Scenario 4: Users signing in for the first time after updating, blocking policies in place
    If a Conditional Access policy blocks a user at the point of Microsoft authentication during sign-in, the user sees a Microsoft-generated message and cannot complete sign-in. The messages and recommended user actions are described in the section above.
    • Admin Action: If users are unexpectedly blocked, the administrator should identify which policy is blocking them (visible in the Microsoft Entra admin center under Conditional Access Sign-in logs) and determine whether the policy is correctly scoped.
       
  • Scenario 5: Bring Your Own Device (BYOD) users with Conditional Access policies not intended for unmanaged devices
    Users with personally-owned devices (BYOD) may be subject to Conditional Access policies that were configured for corporate-owned managed devices. If such a policy requires device enrollment or compliance and the personal device is not enrolled, the user will be blocked.
    • Admin Action: If BYOD users are not intended to be subject to device compliance requirements, they should be excluded from the relevant Conditional Access policy. See the admin guidance section below.

Back to Top ↑

Admin Guidance: Managing Conditional Access Policies

Excluding Users or Groups from a Policy

To prevent specific users from being affected by a Conditional Access policy, IT administrators can add them to the exclusion list of that policy. In the Microsoft Entra admin center, navigate to Protection > Conditional Access, open the relevant policy, and under Users > Exclude, add the users or a security group containing them. The exclude setting overrides the included setting, excluded users will not be subject to that policy regardless of other assignments.

Microsoft recommends creating a dedicated security group for exclusions to make ongoing management easier. See Manage users excluded from Conditional Access policies for guidance including a process for regularly reviewing exclusions.

Ensuring a Device is Enrolled and Compliant

If a Conditional Access policy requires device compliance, the user's device must be enrolled in Microsoft Intune and marked as compliant by Intune's compliance policies. The user enrolls their iOS device through the Microsoft Intune Company Portal app. Once enrolled, Intune evaluates the device against the organization's compliance policies and marks it as compliant or non-compliant accordingly.

For administrator guidance on setting up device enrollment and compliance policies, see device compliance policies in Microsoft Intune and iOS or iPadOS device enrollment guide for Microsoft Intune.

Verifying Which Policy is Blocking a User

Blocked sign-in events are visible in the Microsoft Entra admin center under Users > Sign-in logs or Conditional Access > Insights and reporting. Each blocked event shows which policy applied and which condition was not met, making it straightforward to identify and address the root cause.

Additional Resources

Back to Top ↑

Was this article helpful?
0 out of 0 found this helpful

For technical assistance, please contact us.