Oct 19 2023 02:22 AM
Our org has mainly Macs which are looked after by a different mdm, we also have about 20 Windows 11 devices. We use security defaults on our 365 tenant so do not have access to conditional access. I want to secure the windows devices and stop any windows device from accessing Microsoft apps which is not enrolled in intone. Is this possible without conditional access?
Oct 19 2023 03:19 AM
@robbo215 Do you want to do this for managed Windows devices or also unmanaged ones? If for managed only, you can use Applocker for this. If it's really for all Windows devices I recommend using conditional access. In the MS docs you can see exactly what the security defeault does so I think conditional access is always advantageous.
Oct 19 2023 03:35 AM
Hi @robbo215,
To secure your Windows 11 devices and stop any Windows device from accessing Microsoft apps which is not enrolled in Intune without Conditional Access, you can use the following combination of security features:
Here are some useful links:
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
(LinkedIn)