Forum Discussion

Jason_Benway's avatar
Jason_Benway
Copper Contributor
Nov 29, 2019

Creating new conditional access policy for corporate assets

I want to create a new CA policy that grants access from corporate devices (windows,MAC, and iphones all are Azure hybrid joined or Azure registered ) and if they are not using a corporate device it prompts for their MFA (text or authenticator app)

It looks like my options in the Grant blade are for MFA or hybrid AD joined only. I don't think that includes Azure registered devices? correct?

 

is it possible to included Azure registered devices in a policy to grant access?

 

 

 

  • Thijs Lecomte's avatar
    Thijs Lecomte
    Bronze Contributor
    There is no option to include registered device that is correct.

    Which kind of management do you do on registered devices?
    If you do MAM on those, you could require an app protection policy to be applied?
  • Hello Jason_Benway 

    You have an option i CA to grant/block access depending on if a device meets compliance 

     

    You could perhaps use this to set up a compliance policy that will apply on your other devices.

    Once the devices are compliant the will then be able to access your resources, and be prompted for MFA 

     

    Or you could set up an app protection policy in MAM 

     

    Kind Regards
    Oliwer Sjöberg

Resources