Conditional Access policy to apply if device is the users assigned device

Alex 20 Reputation points
2024-10-16T20:19:49.47+00:00

Not sure if anyone has tried doing something like this before. We are wanting a way to limit when Multifactor Authentication registration can occur for new users. We would like it to be restricted so that they can only access the multifactor registration page if they are accessing it from their assigned computer. I understand this can be done for "compliant devices" but we would like to do it for the specific device assigned to the user attempting to register.

Thanks in advance!

Microsoft Teams
Microsoft Teams
A Microsoft customizable chat-based workspace.
10,184 questions
Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
6,952 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,116 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,910 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sandeep G-MSFT 19,436 Reputation points Microsoft Employee
    2024-10-17T10:33:26.49+00:00

    @Alex

    Thank you for posting this in Microsoft Q&A.

    As I understand you want to create a conditional access policy that will restrict MFA registration page only from device which is assigned to them.

    This requirement is not possible as of now.

    With conditional access you can create a policy to restrict or allow users to access particular apps based on devices platforms, IP addresses, device status, sign-in risks etc. But there is no filter as such to define policy using device owner.

    However, if you are looking for this requirement then you can submit your feedback in Azure feedback portal in below link. This channel is monitored by our PM team directly.

    https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789

    Let us know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


1 additional answer

Sort by: Most helpful
  1. Clément BETACORNE 2,266 Reputation points
    2024-10-17T08:35:59.4666667+00:00

    Hello,

    As far as I know I don't think is possible.

    Regards,

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.