Thank you for posting your query on Microsoft Q&A, from above description I could understand that you are trying to Block access to SharePoint when:
- Device is not in Trusted network Location.
OR
- Device is non complaint/unmanaged.
Please do correct me by responding in the comments section:
- For a Trusted IP location, kindly define an IP range named location.
- Then define a Location based condition including All locations but excluding the "Trusted location"
- In the access control define "Grant Access" with device to be "Complaint"
- Now this CA policy will be evaluating only devices from "Non-Trusted" locations/network for their compliant status, device from "Trusted" network will bypass this policy.
Thanks,
Akshay Kaushik
Please "Accept the answer (Yes)" and "share your feedback ". This will help us and others in the community as well.