Solved
Forti NAC & MDM
I have this policy to assign vlan 17 for devices which not managed by MDM.
But the result why devices managed by MDM also hit this rule?

I have this policy to assign vlan 17 for devices which not managed by MDM.
But the result why devices managed by MDM also hit this rule?

If the MDM is Azure/Intune, kindly check this article: Technical Tip: Microsoft Azure (InTune) Application permission configuration
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.