Home

Conditional Access Policy

%3CLINGO-SUB%20id%3D%22lingo-sub-308051%22%20slang%3D%22en-US%22%3EConditional%20Access%20Policy%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-308051%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20currently%20auto%20registering%20my%20workstations%20with%20AZ%20via%20GPO%20so%20the%20workstations%20display%20in%20AAD%20as%20Hybrid%20joined.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20then%20have%20a%20policy%20applied%20to%20Exch-onLine%20that%20only%20computers%20that%20are%26nbsp%3B%3CSPAN%3EHybrid%20joined%20have%20mailbox%20access.%26nbsp%3B%20This%20is%20to%20stop%20Non-Firm%20computers%20from%20accessing%20Firm%20email.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20issue%20I%20am%20having%20is%20every%20so%20often%20a%20user%20will%20get%20a%20msg%20that%20they%20are%20block%20due%20to%20the%20computer%20not%20being%20Hybrid%20Joined.%26nbsp%3B%20When%20I%20check%20the%20users%20workstation%20i%20run%20DSMCMD.EXE%20%2FSTATUS%20and%20the%20computer%20displays%20as%20Azure%20AD%20Joined.%26nbsp%3B%20I%20check%20the%20AZ%20portal%20and%20the%20computer%20is%20listed%20and%20AAD%20Hybrid%20joined.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EMS%20is%20telling%20me%20that%20the%20workstations%20now%20also%20need%20this%20option%20enabled%26nbsp%3Bin%20the%20GPO%2C%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSTRONG%3E%22Enable%20automatic%20MDM%20enrollment%20using%20default%20Azure%20AD%20credentials.%20%22%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWhich%20will%20now%20display%20the%20workstations%20as%20Mobile%20devices%20and%20will%20show%20up%20as%20either%20incompliance%20or%20not.%26nbsp%3B%20However%20the%20Conditional%20access%20policy%20is%20looking%20for%20the%20device%20to%20be%20Hybrid%20Joined.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ESo%20is%20this%20a%20new%20requirement%20or%20are%20they%20just%20having%20me%20jump%20through%20hoops%20for%20the%26nbsp%3Bheck%20of%20it%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAlso%20wanted%20to%20add%20the%20I%20dont%20see%20this%20option%20in%20the%20Current%20GPPO%20used%20to%20register%20my%20workstations.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20am%20running%20domain%20funtion%20level%20of%202012%20r2.%26nbsp%3B%20They%20are%20telling%20me%20its%20only%20available%20in%20server%202016.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-308051%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-308963%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20Policy%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-308963%22%20slang%3D%22en-US%22%3EAgreed%20the%20user%20however%20was%20on%20the%20internal%20LAN%20and%20launching%20outlook%202016%20which%20is%20why%20this%20threw%20me%20for%20a%20loop.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-308962%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20Policy%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-308962%22%20slang%3D%22en-US%22%3EThats%20what%20I%20thought%2C%20thank%20you.%20I%20will%20get%20back%20with%20them.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-308609%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20Policy%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-308609%22%20slang%3D%22en-US%22%3EMy%20guess%20is%20they%20may%20experience%20this%20issue%20when%20they%20are%20trying%20to%20access%20cloud%20resources%20through%20a%20browser%20which%20is%20not%20supported%20for%20device%20based%20conditional%20access%20and%20therefore%20cannot%20satisfy%20the%20requirement%20so%20gets%20blockedz%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-308595%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20Policy%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-308595%22%20slang%3D%22en-US%22%3EThe%20GPO%20you%20are%20referring%20to%20is%20to%20enroll%20a%20device%20into%20MDM%20and%20is%20only%20required%20if%20your%20CA%20policy%20requires%20compliant%20device.%20If%20you%20simply%20just%20want%20to%20allow%2Fblock%20access%20for%20hybrid%20ad%20joined%20then%20you%20dont%20need%20the%20GPO.%3CBR%20%2F%3E%3CBR%20%2F%3EFYI%20-%20the%20GPO%20is%20part%20of%20the%20windows%2010%201709%20and%20later%20ADMX%20files%3C%2FLINGO-BODY%3E
Frequent Contributor

I am currently auto registering my workstations with AZ via GPO so the workstations display in AAD as Hybrid joined.

 

I then have a policy applied to Exch-onLine that only computers that are Hybrid joined have mailbox access.  This is to stop Non-Firm computers from accessing Firm email.

 

The issue I am having is every so often a user will get a msg that they are block due to the computer not being Hybrid Joined.  When I check the users workstation i run DSMCMD.EXE /STATUS and the computer displays as Azure AD Joined.  I check the AZ portal and the computer is listed and AAD Hybrid joined. 

 

MS is telling me that the workstations now also need this option enabled in the GPO, 

"Enable automatic MDM enrollment using default Azure AD credentials. "

 

Which will now display the workstations as Mobile devices and will show up as either incompliance or not.  However the Conditional access policy is looking for the device to be Hybrid Joined.

So is this a new requirement or are they just having me jump through hoops for the heck of it?

 

Also wanted to add the I dont see this option in the Current GPPO used to register my workstations.

I am running domain funtion level of 2012 r2.  They are telling me its only available in server 2016.

 

 

 

4 Replies
The GPO you are referring to is to enroll a device into MDM and is only required if your CA policy requires compliant device. If you simply just want to allow/block access for hybrid ad joined then you dont need the GPO.

FYI - the GPO is part of the windows 10 1709 and later ADMX files
My guess is they may experience this issue when they are trying to access cloud resources through a browser which is not supported for device based conditional access and therefore cannot satisfy the requirement so gets blockedz
Thats what I thought, thank you. I will get back with them.
Agreed the user however was on the internal LAN and launching outlook 2016 which is why this threw me for a loop.
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies