Conditional access policies to protect company data with computers enrolled using Dem account?

Talha 216 Reputation points
2022-02-22T18:50:47.943+00:00

The client was using Dem account to enroll the devices to intune and now we need to apply conditional access policies to protect company data. I checked the article which has below limitation for Dem account.

• DEM accounts do not support conditional access because conditional access is intended for per-user scenarios.

We are looking to find a way out with out removing or going through the re-enrollment process of all devices. Can we just change the primary user on those PCs from Dem to standard user and conditional access will work? Computer on intune is showing both Enrolled by and primary user as DEM User Email at the moment.

Regards,

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,366 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,085 questions
0 comments No comments
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,406 Reputation points
    2022-02-23T02:40:15.337+00:00

    @Talha Thanks for posting in our Q&A.

    If you want to deploy conditional access policies to windows devices, it is suggested to change the primary user.
    https://learn.microsoft.com/en-us/mem/intune/remote-actions/find-primary-user#change-a-devices-primary-user
    Change the DEM user to a normal user and the normal user is needed to have an Azure Active Directory Premium license.

    Please deploy conditional access policies to this normal users. And use the normal user account to access the resources protected by conditional access policies.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.