Forum Discussion
Conditional Access Policy Not Allowing Users to Access AVD
We have an existing conditional access policy which requires a users' device to be marked as "compliant" in order to access "All Agent Resources". We are trying to deploy an AVD as an alternative to allowing users to use personal devices, but this CA policy seems to be interfering with users being able to access the AVD via Windows App. Yhe device they're accessing from isn't "Compliant" with Intune enrollment being one of the requirements for being compliant. Again, we do not want to allow personal devices into Intune which the MSP allowed previously.
For the CA policy it's applied to all users EXCEPT for specific users in an exclusion group. Putting users in this exclusion group allows them to access the AVD via Windows App but at this point they can just access all resources from their personal machine defeating the purpose of the AVD.
Target Resources
Include All Resources
Exclude: The AVD Itself, Windows 365, Azure Virtual Desktop, Azure Windows VM Sign-in
Conditions
Device Platforms - Windows, MacOS
Client apps - Browser, Mobile apps and desktop clients, exchange ActiveSync clients, other clients are checked
Grant Access
Require MFA and Require device to be marked as compliant are both checked.
Access to the AVD works in the browser but not in Windows App.