enable thunderbird to pass device ID to Azure for ACL to work on Mac
in thunderbird, settings search for Config Editor
then search for security.osclientcerts.autoload, change it from default-false to true
restart thunderbird, it will ask for Azure sign in, picks up a OS Client cert token, MFA if require
now thunderbird client is passing device ID to Azure, which allows ACL to check, deny or allow.