Device compliance in multitenant for CSP

Adrien Maugard 61 Reputation points
2023-07-14T07:42:47.2633333+00:00

Hello all,

I have two existing tenants:

  1. TenantA - Work tenant, containing all my data and services and my work account
  2. TenantB - Admin tenant, containing our tools for our IT activity toward our customers and my admin account.

Let say work@tenantA and admin@tenantB.
Our tenantB is our Cloud Service Provider tenant containing our customer infrastructure access, so is highly sensisive.

Both tenants have their own AAD, name, AAD Connect, nothing is linked, no trust.

All our devices are registered in TenantA and managed for access our company data and such. Conditional Access is in place in this TenantA with MFA requirement and other stuffs.

I need to secure TenantB to require both MFA/Passwordless AND a compliant device

We don't want a second device, and especially no VDI as they would be onprem and defeating the public cloud meaning :D

How can I onboard my device on both tenant without the Hybrid device join (https://learn.microsoft.com/en-us/azure/active-directory/devices/howto-hybrid-azure-ad-join) because this is not what we need as accounts need to be split and not synch from the same AD/Forest.

I'm working on it for a week without a solution, is this even possible?

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
137 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,371 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,576 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 43,381 Reputation points Microsoft Vendor
    2023-07-17T01:40:55.3466667+00:00

    @Adrien Maugard, Thanks for posting in Q&A. From Intune side, it is not recommended to enroll the same device into two different Intune tenants. It will cause issues like policy receiving and etc. I think you still need to consider managing these devices in one tenant.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.