In addition to enforcing login to Prisma Browser itself, you can
restrict access to specific SaaS applications — such as SharePoint, OneDrive, or
the entire Office 365 suite — so they can only be accessed via Prisma Browser
for Intune on mobile devices.
This is useful when organizations want to ensure that corporate
resources are only accessed through a managed, secure browser and not through
Safari, Chrome, or other unmanaged browsers.
How It Works
On Intune-managed iOS and Android devices, Prisma Browser for Intune
can locate and present the device management certificate installed by Intune.
This certificate proves to Entra ID that the device is compliant with your
organization's security baselines.
Other browsers (Safari, Chrome, Firefox, etc.) cannot access this
certificate—even on the same managed device. When a Conditional Access
policy requires a compliant device, these browsers will fail the compliance
check and be blocked.
Note: Native O365 apps (OneDrive, Outlook, Teams) are unaffected
by this configuration. These apps have their own Intune SDK integration and can
independently prove device compliance. Only browser-based access is restricted
to Prisma Browser.