Registering devices with Intune for management and policy enforcement
GSA macOS client: Disable button in Connections window can't be hidden; Compliant Network CA only blocks new M365 sign-ins, not other traffic
We've deployed GSA (Internet Access + TLS inspection) to macOS via Intune and have two open questions:
1. Can't hide/gate the "Disable" button in the new Connections window Since client v1.1.26060207, "Disable" appears in two places: the tray-menu dropdown (hideable via the documented HideDisableButton key; confirmed working) and the new full-screen Connections window (which that key does not affect). We also tried converting the user to a Standard macOS account, expecting UAC-style gating like Windows' RestrictNonPrivilegedUsers, it doesn't gate this action; the client only re-prompts for Entra ID credentials, not a local admin password.
Is there any supported setting to hide/gate the Connections-window Disable button, or is this planned?
2. Compliant Network CA policy only blocks new Microsoft sign-ins, not general traffic We enabled the Compliant Network Conditional Access policy as documented. It works as described: it blocks new Entra ID sign-ins when GSA is disabled, doesn't affect existing sessions or non-Entra-ID traffic. However, disabling GSA stops traffic tunneling and inspection entirely, so Web Content Filtering is bypassed the moment the client is disabled. The CA policy only adds friction for Microsoft apps, it doesn't restore filtering or block general internet access.
Is there a supported way to also restrict general internet access while GSA is disabled, or is Compliant Network purely a token-replay control not meant for this scenario?
Any guidance would be appreciated; I'm happy to share our configuration if useful.