Conditional Access grant that only lets approved client apps in, meaning those that support modern authentication and are Intune-aware. It is commonly offered as an alternative to MFA by choosing Require one of the selected controls.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Require approved client app in context, with comparison tables and the common traps.
Terms in this definition
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Modern authentication
A model where apps rely on a single central identity provider for sign-in and access decisions instead of each handling them alone, which brings uniform policy, single sign-on and better oversight.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.