Configuring ADFS conditional access

Marwen MAJRI 0 Reputation points
2024-01-16T09:59:31.4766667+00:00

We have set up Device Registration and Device Write Back to enable the creation of ADFS Conditionnal Access based on the device trust level (Authenticated, Managed or Compliant). The Computer objects are now synchronized with Miscrosoft Intra Connect and uploaded as Hybrid Joined to Azure. After several attempts and configuration, conditional access only works on Microsoft Intra Registred devices. We want to do this on our Microsoft Intra Hybrid Joined devices. Using ADFSHelp, I've seen that the Token Claims contains no information about the device when it's Hybrid Joined, but with a device in Registred status, the Token Claims contains the information needed to apply conditional access.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,756 questions
{count} votes

1 answer

Sort by: Most helpful
  1. James Hamil 27,016 Reputation points Microsoft Employee
    2024-01-16T22:14:22.3566667+00:00

    Hi @Marwen MAJRI , when a device is Hybrid Joined, the token claims do not contain information about the device. This is because the device is not registered with Azure AD, but rather with your on-premises Active Directory. To apply conditional access policies to your Hybrid Joined devices, you will need to configure device compliance policies in Microsoft Intune. This will allow you to check the compliance status of your devices and apply conditional access policies based on that status. To get started with device compliance policies in Microsoft Intune, you can refer to the following document: Device compliance policies in Microsoft Intune. This document provides step-by-step instructions on how to create and deploy device compliance policies in Microsoft Intune. Once you have configured device compliance policies in Microsoft Intune, you can then use the compliance status of your Hybrid Joined devices to apply conditional access policies. For more information on how to configure conditional access policies in Azure AD, you can refer to this document. Please let me know if you have any questions and I can help you further. If this answer helps you please mark "Accept Answer" so other users can reference it. Thank you, James


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.