I'm having a problem with some computers unable to access applications due to the conditional access policy saying the device is not compliant.

Emmett Carey 51 Reputation points
2023-01-10T19:39:46.98+00:00

This happens to different users on different applications, but it always seems to be an error in the sign in log stating that the device is not compliant, when the device is definitely compliant. One of the errors says: "Device is not in required device state: {state}. Conditional Access policy requires a compliant device, and the device is not compliant. The user must enroll their device with an approved MDM provider like Intune." The device is definitely compliant. I can access other applications with no issues. I only seems to fail on certain applications, and after a reboot it starts to work again. The next day we go through the same issue. The sign in logs always state the device is not compliant, the compliance has never changed.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. JamesTran-MSFT 36,906 Reputation points Microsoft Employee Moderator
    2023-01-20T00:30:29.2966667+00:00

    @Emmett Carey

    Thank you for following up on this!

    Error Message:

    Device is not in required device state: {state}. Conditional Access policy required domain joined device, and the device is not domain joined.

    From the error message within your screenshot, I was able to find a related issue and it looks like the problem could be related to the Primary Refresh Token (PRT) not being present.

    In order to troubleshoot this issue further, I'd recommend working with our support team on this since we'll have to take a closer look at your logs and network traces in order to determine the root cause. For more info - Troubleshoot post-join authentication issues.

    Can you please email me with the info below, I'll go ahead and enable a one-time free technical support request for your subscription so you can work with our support engineers to get this issue resolved.

    Thank you for all of your time and patience throughout this issue!


  2. Kearney Mol 0 Reputation points
    2023-12-07T17:40:30.53+00:00

    Having the same thing with one of my users, Outlook and Teams works but OneDrive does not return device ID and thus is blocked. Works in browser, just not the desktop sync client.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.