Only domain computer can access to company Office365 mailboxes

Federico Coppola 1,181 Reputation points
2021-12-13T21:53:11.32+00:00

Hi all,
In company there is Windows AD domain (Windows Server 2016 domain controllers) and Office365.
In this moment there isn't sync between local Windows AD domain and Azure AD.

All employees use Office365 mailbox and Office365 suite on their laptop.

I know that we can use Azure AD Connect to sync local Active Directory users. Can we use it to sync computer domain?
We need that only company computer can connect company email account.
Our goal is that employees are not going to use personal laptop to read e-mail.
Can we do it?
Do we need InTune license to limit email access just from company laptop?

Thanks in advanced!
Best regards
Federico

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,911 Reputation points MVP
    2021-12-13T22:03:21.18+00:00

    For this scenario, the best approach is to implement CA policy and allow access against compliant devices. You will need to enroll your company devices in Intune and push a compliance policy for this to work correctly.

    1 person found this answer helpful.
    0 comments No comments

  2. Simon Ren-MSFT 40,346 Reputation points Microsoft External Staff
    2021-12-14T02:34:32.467+00:00

    Hi,

    Thanks for posting in Microsoft Q&A forum.

    ==>We need that only company computer can connect company email account.
    Agree with @Rahul Jindal [MVP] . Per my experience, we could use device-based Conditional Access to achieve this goal.

    Intune and Azure Active Directory work together to make sure only managed and compliant devices can access email, Microsoft 365 services, Software as a service (SaaS) apps, and on-premises apps. Additionally, we can set a policy in Azure Active Directory to only enable domain-joined computers or mobile devices that are enrolled in Intune to access Microsoft 365 services.

    For more detailed information, please refer to:
    Device-based Conditional Access
    Guide: Limit Microsoft 365 Access to Corporate Devices with Conditional Access
    Note: The non-Microsoft link is just for your reference.

    Thanks for your time.

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  3. Federico Coppola 1,181 Reputation points
    2021-12-15T16:25:24.383+00:00

    Thanks a lot for your suggestions!

    Federico


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.