Restrict device access based on criteria
You can specify criteria to restrict which devices can access resources.
Steps
-
On the Issuance Criteria tab, in the Source list, select Adapter.
-
Optional: Restrict access based on device ownership:
-
In the Attribute Name list, select Ownership.
-
In the Condition list, select not equal to.
-
In the Value field, type one of the following letters:
-
C (for corporate-owned devices)
-
S (for corporate shared devices)
-
E (for employee-owned devices)
-
-
Click Add, and then click Done.
-
-
Optional: Restrict access based on device operating system:
-
In the Attribute Name list, select OperatingSystem.
-
In the Condition list, select not equal to.
-
In the Value field, type one of the following letters:
-
Apple
-
Android
-
-
Click Add, and then click Done.
-
-
Optional: Restrict access based on device MDM policy compliance:
-
In the Attribute Name list, select ComplianceStatus.
-
In the Condition list, select equal to (case insensitive).
-
In the Value field, type Compliant.
-
Click Add, and then click Done.
-
-
Optional: Restrict access for compromised devices:
-
In the Attribute Name list, select CompromisedStatus.
-
In the Condition list, select not equal to.
-
In the Value field, type True.
-
Click Add, and then click Done.
-
-
Click Done, and then click Next.