Conditional access isn't applied to a group of users on a separate domain

Pavel Kotelevskii 0 Reputation points
2024-12-06T05:56:34.8066667+00:00

We have a small group of users on a separate domain which is part of the same tenant at our main domain. We've discovered that conditional access policies are not being applied to that group of users. CA policies are applied to all users. Also, sign in logs don't pick up the Device ID and Join Type for the users in question. All of them use BYOD devices.

Microsoft Security | Intune | Configuration
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. EduardsGrebezs 1,176 Reputation points
    2025-07-23T08:42:46.4533333+00:00

    Hi,

    For BYOD:

    • If the device is not registered in Entra ID (Azure AD), then:
      • No Device ID or Join Type shows in logs.
      • Device-based CA conditions (e.g., “Require compliant device”) won’t apply.
      • Entra ID treats it as an unregistered device, which may bypass or block some policies depending on configuration

    Did you tried to check using "What if" function for that specific domain users which of your Entra ID CA applies to them?

    1. Go to the Microsoft Entra admin center.
    2. Navigate to: ProtectionConditional AccessWhat If
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.