Restrict device access based on criteria
You can specify criteria to restrict which devices can access resources.
Steps
-
On the Issuance Criteria tab, in the Source list, select Adapter.
-
(Optional) Restrict access based on device ownership:
-
In the Attribute Name list, select Ownership.
-
In the Condition list, select not equal to.
-
In the Value field, enter one of the following letters:
-
C
: For corporate-owned devices. -
S
: For corporate shared devices. -
E
: For employee-owned devices.
-
-
Click Add, and then click Done.
-
-
(Optional) Restrict access based on device operating system:
-
In the Attribute Name list, select OperatingSystem.
-
In the Condition list, select not equal to.
-
In the Value field, enter one of the following:
-
Apple
-
Android
-
-
Click Add, then Done.
-
-
(Optional) Restrict access based on device MDM policy compliance:
-
In the Attribute Name list, select ComplianceStatus.
-
In the Condition list, select equal to (case insensitive).
-
In the Value field, enter Compliant.
-
Click Add, then Done.
-
-
(Optional) Restrict access for compromised devices:
-
In the Attribute Name list, select CompromisedStatus.
-
In the Condition list, select not equal to.
-
In the Value field, enter True.
-
Click Add, then Done.
-
-
Click Done, then Next.