Conditional access policy not working even though device is compliant

Shelby Simpson 20 Reputation points
2024-12-09T21:34:40.5666667+00:00

Conditional access in not working with a user even though their laptop is compliant in Intune.

Microsoft Security Microsoft Entra Other
{count} votes

3 answers

Sort by: Most helpful
  1. Abiola Akinbade 29,405 Reputation points Volunteer Moderator
    2024-12-09T23:01:05.4266667+00:00

    Hello Shelby Simpson,

    Thanks for your question

    Since the issue follows the user and not the device, it is likely tied to the user’s identity or account configuration

    Try to go to entra on the portal and

    • Go to Protection > Conditional Access > Policies then check heck the Users and groups assignment to ensure the user is included.
    • Check the device’s compliance status to ensure it reflects correctly.

    See: https://learn.microsoft.com/en-us/mem/intune/protect/conditional-access?source=recommendations

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    Regards,

    Abiola


  2. Bandela Siri Chandana 3,055 Reputation points Microsoft External Staff Moderator
    2024-12-11T16:35:34.95+00:00

    Hi @Shelby Simpson
    Thank you for posting your query on Microsoft Q&A.
    I understand that Conditional access policy in not working with user even though your laptop is compliant in Intune.

    The conditional access policy will only validate the device as Intune if the device ID is successfully sent from the browser to Azure. If the Device ID does not pass through the policy, Azure will be unable to recognize the device state without it. Make sure you're using compatible browsers for device authentication, so the device can be detected and validated against the policy. When using a browser, there are various settings that must be made on the browser in order to transfer the device information. For example, if you are using an Edge browser, the user profile in the browser must be synced and the synced status must be enabled in order to send the device ID.

    User's imagePlease check below screenshot for browser requirement 

    User's imageFollow the document: Conditions in Conditional Access policy - Microsoft Entra ID | Microsoft Learn

    If still problem persists. Check whether all the conditions are met in the following document: Troubleshoot Intune Conditional Access - Intune | Microsoft Learn

    Hope this helps. Do let us know if you have any further queries. 

    ------------  

    If this answers your query, do click `Accept Answer` and `Yes`.

    Thanks,

    B. Siri Chandana.


  3. Mohammed Altamash Mohammed Suleman Khan 2,331 Reputation points
    2024-12-20T13:17:13.93+00:00

    Hi @Shelby Simpson

    Recently we have completed same project, and i saw your question. I can help you on this but i need more info.

    1. Can you share me login error. (click on more detail and take complete screenshot). It will tell us if the issue is with browser & Device ID passthrough.
    2. This case is for corporate device ? Have you tried from Corporate and Personal Network. Most Corporates used proxy or CASB solutions which block Device ID. Do you see any change in URL if you visit portal.azure.com in both network.
    3. If it satisfy the condition of device compliant , What are we allowing ? Are you verifying it correctly ?

    Regards

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.