How to Fix a Blocked Microsoft Sign-In on Your Mac, iPhone, or iPad
Troubleshooting: Apple device blocked at sign-in
If you were directed here after a sign-in error, your Apple device didn't pass Stanford's device check. To protect Stanford data, Microsoft only allows sign-ins from devices it can confirm are set up with Stanford and kept secure. When it can't confirm that, it blocks the sign-in, even if your SUNet ID and password are correct.
This is usually straightforward to fix. There are three common causes listed in the table below. If you're not sure which cause applies to you, start with Check your device status.
Check your device status
On the device that was blocked, go to the Microsoft Company Portal website and sign in with your sunetid@stanford.edu account. Look for the device you're using in the device list:
- Your device isn't listed: it isn't registered with Microsoft yet. See Cause 1 below.
- Your device is listed but doesn't say "Managed by Jamf Device Compliance": it isn't connected to Stanford's device management. See Cause 3 below.
- Your device is listed and looks correct: the app or browser you're signing in with may not be sharing device information. See Cause 2 below.
| Cause | What's happening | How to fix |
|---|---|---|
| Cause 1: Your device isn't registered with Microsoft | Your Mac, iPhone, or iPad needs a one-time registration so Microsoft can recognize it as your device. Until that's done, sign-ins are blocked. |
Note: After registering, allow up to one hour for your device's status to update, then try signing in again. |
| Cause 2: Your app or browser can't share device information | Even a registered device is blocked if the app or browser you're using can't tell Microsoft which device it is. |
|
| Cause 3: Your device isn't enrolled in Stanford Jamf | Stanford uses a tool called Jamf to confirm your device meets security requirements (like an up-to-date operating system and a passcode or encryption). If your device isn't enrolled in Jamf, Microsoft has no way to confirm it's secure and blocks the sign-in. |
Note: Devices purchased through Stanford (such as SmartMart or the university bookstore) enroll in Jamf automatically during initial setup. If you bought your device elsewhere, you'll need to enroll it yourself using the steps above. |
Still blocked?
- Give it time. Status updates can take up to one hour after you register or enroll, and up to 24 hours in some cases.
- Check your device meets security requirements. Your device must also run a current operating system and be secured — FileVault encryption on a Mac, a passcode on an iPhone or iPad. See macOS compliance requirements or iOS/iPadOS compliance requirements.
- Contact us. If you've worked through the causes above and still can't sign in, submit a help ticket or call the UIT Service Desk at 650-725-4357 (5-HELP).
