Conditional Access policy to apply if device is the users assigned device

Alex 20 Reputation points
2024-10-16T20:19:49.47+00:00

Not sure if anyone has tried doing something like this before. We are wanting a way to limit when Multifactor Authentication registration can occur for new users. We would like it to be restricted so that they can only access the multifactor registration page if they are accessing it from their assigned computer. I understand this can be done for "compliant devices" but we would like to do it for the specific device assigned to the user attempting to register.

Thanks in advance!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
Microsoft Security | Intune | Other
Microsoft Teams | Microsoft Teams for business | Other
0 comments No comments
{count} votes

Accepted answer
  1. Sandeep G-MSFT 20,906 Reputation points Microsoft Employee Moderator
    2024-10-17T10:33:26.49+00:00

    @Alex

    Thank you for posting this in Microsoft Q&A.

    As I understand you want to create a conditional access policy that will restrict MFA registration page only from device which is assigned to them.

    This requirement is not possible as of now.

    With conditional access you can create a policy to restrict or allow users to access particular apps based on devices platforms, IP addresses, device status, sign-in risks etc. But there is no filter as such to define policy using device owner.

    However, if you are looking for this requirement then you can submit your feedback in Azure feedback portal in below link. This channel is monitored by our PM team directly.

    https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789

    Let us know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


1 additional answer

Sort by: Most helpful
  1. Clément BETACORNE 2,496 Reputation points
    2024-10-17T08:35:59.4666667+00:00

    Hello,

    As far as I know I don't think is possible.

    Regards,

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.