How to restrict the other domains and user accounts to use and enroll the device and use apps and add in a domain enrolled device via Intune, Entra ID etc. and what are the ways to do it?

Mytoast Admin 285 Reputation points
2024-09-13T16:02:56.48+00:00

How to restrict the other domains and user accounts to use and enroll the device and use apps and add in a domain enrolled device via Intune, Entra ID etc. and what are the ways to do it?

For example: I don't want users to user other domains user accounts to use with any of the M365 apps and services on the my domain enrolled machines.

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,569 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,941 questions
{count} votes

Accepted answer
  1. Raja Pothuraju 22,885 Reputation points Microsoft External Staff Moderator
    2024-09-24T01:39:59.3933333+00:00

    Hello @Mytoast Admin,

    Thank you for posting your query on Microsoft Q&A.

    Based on your description, I understand that you are trying to restrict access to users from other domains on your company’s corporate devices. For example, if a device is part of Tenant A, users should only be able to log in to browser-based applications using credentials from your tenant. If someone attempts to log in with credentials from another tenant (e.g., Tenant B), access should be restricted. Please correct me if I’ve misunderstood.

    To address this requirement, I’d like to share an alternative approach you can consider. Below, you will find a flowchart illustrating Tenant Restrictions V2.

    Diagram illustrating tenant restrictions v2.

    As shown in the flowchart, if a user on a Contoso-managed device tries to access resources using credentials from an unknown tenant, the login will be restricted. For more details, please refer to the following documentation:

    tenant restrictions v1

    tenant restrictions v2

    Universal tenant restrictions

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,
    Raja Pothuraju.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 17,165 Reputation points Microsoft External Staff
    2024-09-16T06:20:19.13+00:00

    @Mytoast Admin, Thanks for posting in Q&A.

    From your description, I know you want to restrict the other domains and user accounts to use and enroll the device and use apps and add in a domain enrolled device via Intune.

    Based on my research, for Windows, we can configure Automatic Enrollment under Enrollment restrictions to Some and select the user account that you want to enroll in Intune and create a conditional access policy that require device must be marked as compliant so that they can access apps

    User's image

    For Android device and iOS device, we can create an app protection policy to restrict some user's access.

    https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-android#conditional-launch

    https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-ios#conditional-launch

    Hope above information can help you, if there is any update, feel free to let me know.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.