Forum Discussion
Problem with Conditional Access rule Use app-enforced Restrictions for browser access.
Yes i tested it on a other device and there works a expected.
The device id i got from dsregcmd is the same as in Azure.
I'd like to know why this partical device doesn't show the device info properly and how to fix it, whithout resetting the device. I have had two other devices with the same issue.
What does the 'device state' say?
- PKlapwijkMar 31, 2020MVP
RonaldvdMeer Hi Ronald,
Hard to troubleshoot these kind of issues. The issue is that when no Device ID is send, no compliance check is done.
But what is the cause.... No idea from this place. - RonaldvdMeerMar 31, 2020Iron Contributor
I did not see any difference between the dsregcmd status of a working device and the device that didn't work.
dsregcmd /leave did work
but dsregcmd /join didn't i got the message failed to complete task.
The only option left after that was a clean install of the device.
After complete rollout of the device the conditional access rules work as expected.
So problem is solved, although i am curious how this could have happened.
- RonaldvdMeerMar 27, 2020Iron Contributor
I will do that next Monday. I am working from home right now due to..... You know.
I will roll out a new device. See what happens.
I will get back to you next Monday
- PKlapwijkMar 27, 2020MVP
RonaldvdMeer seems that something is wrong with the AAD registration as no Device ID is send and without that compliance status isn`t checked (and fails).
You should compare the outcome of dsregcmd /status as Thijs says, from a working Windows device with a none working. See if there is a difference which can point you in the right direction.
You can also trydsregcmd /leave
dsregcmd /join
Restart the laptop and try again.
- RonaldvdMeerMar 27, 2020Iron Contributor
- Thijs LecomteMar 27, 2020Bronze ContributorAre you logged in with a local user or an AAD user?
- RonaldvdMeerMar 27, 2020Iron Contributor
- Thijs LecomteMar 27, 2020Bronze ContributorThat looks good...
If you try using the 'old' Edge or IE, does it report back then? - RonaldvdMeerMar 27, 2020Iron Contributor
+----------------------------------------------------------------------+
| Device State |
+----------------------------------------------------------------------+AzureAdJoined : YES
EnterpriseJoined : NO
DomainJoined : NO - Thijs LecomteMar 27, 2020Bronze ContributorPleae share the entire Device State bit.
EnterpriseJoined : x
AzureADJoined: x
... - RonaldvdMeerMar 27, 2020Iron Contributor