Hello @Srinivas Pasupuleti - CyberSecurity,
Thank you for posting your query on Microsoft Q&A.Based on your description, I understand that you have on-premises domain-joined devices and some Azure AD Registered devices. Your goal is to block access to OneDrive and SharePoint on these devices via a conditional access policy. You created a block policy and excluded Microsoft Entra Registered devices, which works fine for Entra Registered devices but not for on-premises domain-joined devices.
To make it work with domain-joined devices, you need to convert those devices to Microsoft Entra hybrid-joined devices by syncing them from on-premises to the cloud using Microsoft Entra Connect. Once the on-premises domain-joined devices become Microsoft Entra hybrid-joined devices, you can exclude them from your block conditional access policy and restrict access to OneDrive and SharePoint as per your requirements.
Please follow the document below to convert on-premises domain-joined devices to Microsoft Entra hybrid-joined devices:
https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join
By using the filter for device conditions in the conditional access policy, you can exclude those devices from the policy. Please refer to the document below to learn more about the supported operators and device properties for filters:
https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-condition-filters-for-devices
I hope this information is helpful. Please feel free to reach out if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.
Thanks,
Raja Pothuraju.