Struggling with Bypassing MFA for Devices Joined via Azure Hybrid AD in Conditional Access Policy

Diego 0 Reputation points
2023-05-21T09:49:05.98+00:00

Hello everyone, I'm having a problem when implementing a conditional access policy: I have devices joined using an Azure Hybrid AD join mode, and I'm trying to bypass these devices from applying two-factor or MFA through a conditional policy, but I've tried everything, excluding the IDs, excluding all devices joined in this Azure Hybrid way and it's just not working. What step am I missing?

thanks

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,689 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Michael Maher 42 Reputation points
    2023-05-21T10:05:02.79+00:00

    Can you used the WhatIf tool to see the result of the Conditional Access policies for the given sign-in scenario.

    Also the sign-in logs have a tab which should help.

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/troubleshoot-conditional-access#policy-not-working-as-intended

    If all else fails there is s template Conditional Access policy which might help.
    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-compliant-device#template-deployment