The settingWhat we hold this to
CreativeTechs minimum
A CA policy in state ENABLED, All users, Conditions → Device platforms → Include Any device, Exclude macOS, iOS, iPadOS, Windows; grant = Block. Adjust the exclusion list per client to the platforms they actually run.
Benchmark position
No published benchmark value. Huntress ships 'Block Unused Device Types' as a managed CA template, rated High · Foundational.
Where we differ, and why
Ours plus Huntress. Cheap for an Apple fleet and worth the audit it forces — it is how you discover the personal Android nobody mentioned.
Where the switch is
Entra admin centre → Protection → Conditional Access → Policies → New policy → Conditions → Device platforms.
How to verify
Graph: /identity/conditionalAccess/policies → conditions.platforms.includePlatforms/excludePlatforms
- Why it matters
- An Apple shop with a handful of PCs has no reason to accept sign-ins from Linux or Android. Every platform you don't use is attack surface nobody is watching.
- How we check
- Huntress managed CA template 'Block Unused Device Types' (High · Foundational).
- Fix — M365
- CA policy → Device platforms → block everything except macOS, iOS, iPadOS and Windows.
- Fix — Google
- Context-Aware Access device policies.
- User notices
- Nothing, until someone signs in from an unusual platform — either a new hire's Android or an intruder.
- Expected pushback
- Low, but audit first: personal Android phones checking mail are more common than anyone admits. Unusually cheap for an Apple fleet, which is most of the book.
