Device identification and MDCA policy application

Bob Builder 0 Reputation points
2024-07-13T02:38:13.54+00:00

We wish to apply an MDCA policy to non corporate (BYOD) devices that will block the ability to use locally installed O365 apps and to access via browser only. We also wish to block file downloads from the O365 apps in scope to the local machine on the BYOD devices. These apps are accessed using Entra ID accounts. Access to these apps on corporate devices is to remain as is and NOT have the policy applied. What is the best method to identify corporate devices (Windows and MACs) so that we can apply the MDCA policy to those devices NOT identified as a corporate? Thanks

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Pauline Mbabu 1,080 Reputation points Microsoft Employee
    2024-07-29T11:49:58.9333333+00:00

    Hello @Bob Builder ,

    Thank you for your question.
    To achieve this, you use Intune to mark the cooperate devices are compliant the use Conditional to block non-compliant devices. Kindly look at this doc: https://learn.microsoft.com/en-us/defender-cloud-apps/use-case-proxy-block-session-aad

    0 comments No comments

  2. Pauline Mbabu 1,080 Reputation points Microsoft Employee
    2024-07-29T12:30:40.77+00:00

    Hello @Bob Builder ,

    Thank you for your question. To achieve this, you can use Intune to make the corporate devices compliant then use Conditional to block non-compliant devices.  Kindly look at this doc: https://learn.microsoft.com/en-us/defender-cloud-apps/use-case-proxy-block-session-aad

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.