Conditional access behavior desired

Sergi Díaz Ruiz 240 Reputation points
2023-10-09T16:48:35.7366667+00:00

Afternoon !

I need answer to my doubts about the behavior of conditional access.

When I configure conditional access based on compliances device for cloud apps.

In targets I select only device's , NOT users. Is correct?

When user log in device with not compliance in Intune for example I configured compliance policy for firewall enabled. The users can join to cloud apps¿?

How works this? Please don't send me the article of Microsoft about conditional access.. I think if we configured the devices on conditional access, the users logged in these device's cant access to cloud apps... But is not working. If I configure the conditional access for devices + users, then yes, it works.

Regards

Microsoft Security Intune Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2023-10-10T01:53:28.8+00:00

    @Sergirash rash baix, Thanks for posting in Q&A. For conditional access, it controls if the user can access resource when they sign in. Under assignment, we can only assign it user or user group. We can't assign it to device group.

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-users-groups

    When the user sign in request is sent, it finds the devices needs to be compliant. It will check the compliance status of the device. If it is not compliant, it will block the access. If the device is not enrolled, it will ask to download company portal to do the enrollment.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2023-10-18T07:07:55.73+00:00

    @Sergirash rash baix, Thanks for the reply. conditional access policy can only be applied to user group. If the user logs in to not compliance device, they will receive error which mentioned the access is blocked by your organization.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.