Nov 14 2018 02:57 AM
Hi All
Tricky scenario here and I will try my best to explain.
Conditional Access Policy for BYOD / Personal devices = Require approved app
Conditional Access Policy for Corp devices = Require approved app AND Require compliance
If both are assigned to the same group:
Ideally we would like a separate CA policy for BYOD and Corp where users are in the same group and may have a Corp AND Personal device.
Any help or hints would be great.
Stuart
Nov 20 2018 01:03 PM
You should be able to do this by using Dynamic Device Groups and using a rule like (device.deviceOwnership -eq "Company") for your Corporate devices. In general, the more restrictive policy will take precedence.
Nov 22 2018 04:03 AM
Solutionthe thing is that at the moment CA supports only user based groups, so you won't be able to target separate policies based on device type.
I was told that it's something in plan, but no ETA.
Feb 26 2019 10:01 AM - edited Feb 26 2019 10:02 AM
Feb 26 2019 10:01 AM - edited Feb 26 2019 10:02 AM
I have the same need to allow same user to have both corp & BYOD devices with separate policies for each. Am looking for this in 365 business
Jun 17 2019 12:59 PM
@Stuart King Same need here. Hope there is a solution provided for this at some point.