Skip to main content

How to Fix a Blocked Microsoft Sign-In on Your Mac, iPhone, or iPad

Troubleshooting: Apple device blocked at sign-in

If you were directed here after a sign-in error, your Apple device didn't pass Stanford's device check. To protect Stanford data, Microsoft only allows sign-ins from devices it can confirm are set up with Stanford and kept secure. When it can't confirm that, it blocks the sign-in, even if your SUNet ID and password are correct.

This is usually straightforward to fix. There are three common causes listed in the table below. If you're not sure which cause applies to you, start with Check your device status. 

Check your device status 

On the device that was blocked, go to the Microsoft Company Portal website and sign in with your sunetid@stanford.edu account. Look for the device you're using in the device list:

  • Your device isn't listed: it isn't registered with Microsoft yet. See Cause 1 below. 
  • Your device is listed but doesn't say "Managed by Jamf Device Compliance": it isn't connected to Stanford's device management. See Cause 3 below. 
  • Your device is listed and looks correct: the app or browser you're signing in with may not be sharing device information. See Cause 2 below. 
CauseWhat's happeningHow to fix
Cause 1: Your device isn't registered with MicrosoftYour Mac, iPhone, or iPad needs a one-time registration so Microsoft can recognize it as your device. Until that's done, sign-ins are blocked.

Note: After registering, allow up to one hour for your device's status to update, then try signing in again.

Cause 2: Your app or browser can't share device informationEven a registered device is blocked if the app or browser you're using can't tell Microsoft which device it is.
  • Use a supported browser. On a Mac, use Safari, Microsoft Edge, or Google Chrome. Firefox requires extra configuration first — see the Microsoft Login + Intune FAQs. On an iPhone or iPad, use Safari or Microsoft Edge. 
  • Use an app that supports modern Microsoft sign-in. Only applications built with Microsoft's modern authentication libraries can share device information at sign-in. Older or homegrown software typically doesn't include this support and will be blocked even on a correctly set-up device. If a specific app keeps failing, try a current Microsoft app or a supported browser instead.
  • Avoid private browsing. Sign in from a regular browser window. 
  • On iPhone or iPad, keep Microsoft Authenticator installed. Authenticator is what shares your device's information with Microsoft during sign-in. If you removed it, reinstall it from the App Store.
Cause 3: Your device isn't enrolled in Stanford JamfStanford uses a tool called Jamf to confirm your device meets security requirements (like an up-to-date operating system and a passcode or encryption). If your device isn't enrolled in Jamf, Microsoft has no way to confirm it's secure and blocks the sign-in.

Note: Devices purchased through Stanford (such as SmartMart or the university bookstore) enroll in Jamf automatically during initial setup. If you bought your device elsewhere, you'll need to enroll it yourself using the steps above.

Still blocked? 

  • Give it time. Status updates can take up to one hour after you register or enroll, and up to 24 hours in some cases. 
  • Check your device meets security requirements. Your device must also run a current operating system and be secured — FileVault encryption on a Mac, a passcode on an iPhone or iPad. See macOS compliance requirements or iOS/iPadOS compliance requirements
  • Contact us. If you've worked through the causes above and still can't sign in, submit a help ticket or call the UIT Service Desk at 650-725-4357 (5-HELP).
Last modified