How to integrate Microsoft RADIUS server with conditional access policy

Belinda 0 Reputation points
2024-04-16T03:39:49.7066667+00:00

Can someone assist me in this please?
Our company has an existing Microsoft RADIUS Server to identify if it is corporate device before it can access to corporate network.
Now, we would like to integrate Microsoft RADIUS Server with Conditional access policy such that when the device is not compliant with the Intune compliance policy and configuration policy even if it is a corporate device, it will not be able to access any resources (on-premise and cloud applications). Is this possible?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,729 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,560 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Navya 4,005 Reputation points Microsoft Vendor
    2024-04-22T06:06:05.3966667+00:00

    Hi @Belinda Thank you for posting this in Microsoft Q&A.

    I understand you want integrate Microsoft RADIUS server with conditional access policy.

    Yes, it is possible to integrate Microsoft RADIUS Server with Conditional Access policy to restrict access to corporate resources for non-compliant devices. You can use the "Require device to be marked as compliant" control in the Conditional Access policy to ensure that only compliant devices can access resources.

    To configure this, you need to create a new Network Policy in the Network Policy Server management console and select "Remote Access Server (VPN-Dial up)" as the network access server type.
    For your reference: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure

    Once the Network Policy is created, you can create a new Conditional Access policy in the Microsoft Entra Id and select the "Require device to be marked as compliant" control. This will ensure that only compliant devices can access corporate resources, even if they are corporate devices.

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-policy-compliant-device#create-a-conditional-access-policy

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.

    If the answer is helpful, please click "Accept Answer" and kindly" upvote" it.