A cloud-based identity and access management service for securing user authentication and resource access
Technically, yes as CA simply blocks non-compliant devices. Compliance can be defined in many different ways but there is no built-in rule in AD or Intune to check for the presence of a cert.
What's the use case here where a cert would be required for a compliant device? How does this cert get onto the devices and what is it used for? Are these fully managed devices or is this a MAM scenario?