cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4253
Views
10
Helpful
5
Replies

AnyConnect 4.10.05095 - WebView2 Breaks Azure AD Conditional Access

msaringer
Level 1
Level 1

Hello,

 

Since upgrading to AnyConnect 4.10.05095 we've found that our Windows clients no longer report device information as part of the SAML sign-in process which causes them to fail Conditional Access policies that require a domain-joined or InTune compliant device check. Users instead get an error that they are attempting to access a resource that requires a domain-joined device from a personal device and are unable to complete the SAML sign-in.

 

Looking at the Azure AD sign-in logs we can see the upgraded clients don't show the Device ID or information about the device state beyond a generic Edge User Agent. For comparison devices using previous versions of AnyConnect show the Azure AD Device ID and information about the device. This seems to be related to a setting in the implementation of the WebVew2 component as is documented here: https://github.com/MicrosoftEdge/WebView2Feedback/issues/550

 

For now we've reverted to using the registry key workaround documented in the AnyConnect release notes for 4.10.05095 but this is a pain to deploy and I'm not certain it will continue to operate as Microsoft phases out IE 11.

 

Has anyone been able to get WebView 2 working with device-based Conditional Access?

 

Thanks!

1 Accepted Solution

Accepted Solutions

This issue will be resolved in the next release of AnyConnect.  For now the registry key must be used.

View solution in original post

5 Replies 5

stsargen
Cisco Employee
Cisco Employee

Please check your private messages regarding this issue.

 

Thanks,

Steve S.

We are having the same exact issue in our environment. Can you share the resolution for this?

This issue will be resolved in the next release of AnyConnect.  For now the registry key must be used.

Any insight on when that fixed version will be available?

 

Thanks,

Paul

 

This was just posted to CCO.  version 4.10.05111