Forms blocked by Conditional access policy

Brennan Marquez 20 Reputation points
2026-10-01T23:46:30.94+00:00

I have several users where on their personal devices, they are not able to access Microsoft forms. It appears to be blocked by a conditional access policy in Entra. That all makes sense until it is blocked on safari on the iPhones but then not blocked on Edge. Is there a policy condition that I am not seeing that allows/disallows specific browsers on devices?

Microsoft Edge | Other | iOS
0 comments No comments

2 answers

Sort by: Newest
  1. EmilyS_726 30,175 Reputation points Volunteer Moderator
    2026-10-02T00:29:02.92+00:00

    It sounds like the policy is not actually blocking Safari specifically. More likely, the CA policy is requiring something that Edge can satisfy, but Safari cannot.

    On iPhone, this can happen if the policy is set to Require app protection policy or the older Require approved client app. Edge can meet that requirement when the user is signed in with the work account, but Safari cannot, so you end up with Safari being blocked while Edge works on the same device.

    Check the failed Safari sign-in in:

    Entra admin center > Identity > Monitoring & health > Sign-in logs > open the failed sign-in > Conditional Access

    That should show exactly which policy blocked it. Then compare it with a successful Edge sign-in from the same user/device.

    Especially look at the Grant controls and see if Require app protection policy is enabled. That would fit this behavior pretty well.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-10-01T23:46:42.0866667+00:00

    Yes. Conditional Access can effectively allow or block access differently by browser on iPhone because browser support for device-based and app-based controls is different.

    On iOS:

    • Microsoft Edge and Safari are both supported for device-based Conditional Access on a managed device.
    • Safari cannot satisfy the Require approved client app or Require app protection policy conditions.
    • A managed browser like Microsoft Edge can satisfy approved client app and app protection policy requirements.
    • On iOS with non-Microsoft MDM solutions, only Microsoft Edge supports device policy.

    That means if the policy protecting Forms includes controls such as:

    • Require approved client app, or
    • Require app protection policy

    then Safari on iPhone can be blocked while Edge is allowed.

    A practical way to confirm this is:

    1. In the failed sign-in, open Microsoft Entra ID sign-in logs.
    2. Select the failed request.
    3. Check Basic info for the failure reason.
    4. Open the Conditional Access tab to see which policy is causing the block.

    Also note:

    • If the device is managed, Safari can work for device-based Conditional Access, but not for app protection or approved client app requirements.
    • If users see a browser access issue in Edge, Microsoft documents that Edge profile identity must match the identity accessing the resource.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.