Fix Microsoft Defender Android Sign-In Blocked by Intune
Question details
Users are unable to sign into the Microsoft Defender app on Android devices due to an Intune app protection policy conflict.
- Product
- Microsoft Defender for Endpoint / Microsoft Intune
- Device & OS
- Android (e.g., Xperia 1 VI)
- Scenario
- Attempting to access Microsoft Defender on an Android mobile device managed by organizational Conditional Access policies.
- Observed behavior
- The application displays a 'You can't get there from here' error, and Intune incorrectly reports that Defender is unavailable for app protection policies despite being approved.
Ensure you have administrative access to the Microsoft Intune admin center and Entra ID to review compliance policies and conditional access configurations.
Audit Intune Policies and Escalate to Microsoft Support
Since this is a known technical limitation regarding Intune's recognition of the Defender app, administrators must manually verify policy assignments and submit a diagnostic ticket to Microsoft.
Currently, there is an ongoing backend issue where Microsoft Intune fails to recognize Microsoft Defender for Mobile as an applicable target for certain App Protection Policies (MAM), leading to unwarranted sign-in blocks. Standard users cannot bypass this error locally.
Log in to the Microsoft Entra admin center, navigate to Protection > Conditional Access, and verify if any active policies requiring an 'Approved client app' are unintentionally blocking Microsoft Defender.
Open the Microsoft Intune admin center, go to Apps > App protection policies, and confirm whether Microsoft Defender is correctly included in the targeted apps list for Android devices.
Ask the affected user to open the Intune Company Portal app on their Android device, shake the device or use the help menu to collect diagnostic logs, and note the correlation ID associated with the 'You can't get there from here' error.
In the Endpoint Manager admin center, navigate to Troubleshooting + support and open a new support request. Provide the device model, OS version, application status, and the diagnostic logs to Microsoft engineers for further investigation.
Maintain Mobile Productivity with WPS Office
While dealing with complex Intune and Microsoft Defender conditional access blocks, keep your team productive with WPS Office. It provides a lightweight, hassle-free alternative for managing documents on Android without encountering disruptive MDM sign-in loops.

Frequently Asked Questions
Why does Microsoft Defender say 'You can't get there from here' on my Android phone?
This error occurs because your organization's Microsoft Entra Conditional Access policies require you to use an approved app or app protection policy. Due to a configuration or system glitch, Intune does not recognize Defender as meeting these requirements on your specific device.
Is Microsoft Defender supported by Intune App Protection Policies?
While Defender integrates with Intune for device compliance, there are known backend limitations where Intune may incorrectly report Defender as unavailable for targeted App Protection Policies (MAM), which triggers sign-in blocks.
Can I bypass the Conditional Access block on my mobile device myself?
No, end-users cannot bypass organizational access controls manually. Your IT administrator must adjust the Conditional Access rules in the Microsoft Entra portal or escalate the issue to Microsoft Support to resolve the policy conflict.




