defender & intune-restrict access to a website based on device risk level

michal 191 Reputation points
2023-06-13T22:01:41.91+00:00

Hi all,

is it possible to restrict access to a public website based on a risk level calculated by defender? Lets say that if a device has HIGH risk level, it will not be allowed to access particular web site....

PS: We use M365 E3 with M365 E5 Security addon.

Thank you.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
366 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
117 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 45,086 Reputation points Microsoft Vendor
    2023-06-14T01:54:23.91+00:00

    @michal, Thanks for posting in Q&A.

    For the web site, if it is related with the cloud app in Conditional access, maybe we can create conditional access policy to block the access according to the risk score.

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-cloud-apps#microsoft-cloud-applications

    We can create a compliance policy and mark the device at or under the machine score as non-compliant:

    https://learn.microsoft.com/en-us/mem/intune/protect/compliance-policy-create-windows#microsoft-defender-for-endpoint-rulesdevice

    Then you can create conditional access policy to require a compliant device to block the non-compliant device access to the cloud resource:

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-compliant-device

    However, if the above information can not help, you can contact Microsoft Defender for Endpoint support in the following link to see if it can be done there:

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/contact-support?view=o365-worldwide

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Pavel yannara Mirochnitchenko 12,381 Reputation points MVP
    2023-06-14T05:54:25.01+00:00

    Just an idea - if you limit access to local M365 apps, users will do anything to fix it :)

    0 comments No comments