Forum Discussion
SebCerazy
Nov 14, 2022Iron Contributor
Conditional Access for Azure AD ONLY joined devices
All my user mobile devices (Windows based) are Azure AD joined (no hybid) The requirement is to allow access to online resources from these devices ONLY & if external to trusted location then do MFA...
Try using filters in EndPoint Manager/Intune https://learn.microsoft.com/en-us/mem/intune/fundamentals/filters
SebCerazy
Nov 15, 2022Iron Contributor
?????
And what would that do to my Conditional Access in Azure?
And what would that do to my Conditional Access in Azure?
- Nov 15, 2022CA checks the compliance policies. Don’t allow personal devices to be compliant.
- SebCerazyNov 15, 2022Iron ContributorPersonal devices (not Azure joined) are NEVER compliant, so that is not an issue!
But as explained, I can NOT chose just the compliance condition (because that does not work 100% every time, for reasons mentioned).- Nov 15, 2022Well, if BYOD are never compliant the world would have issues right now. And what's up with the language? This is a community where people help each other.
I haven't heard of your third-party compliance issue before. Perhaps check with Sophos...
If filtering of any kind is not an option perhaps you need to look at Defender for Cloud Apps using an Access policy with a Block action.