@Cloud Backup MM , For the picture, we would like to confirm if it is coming after we login one application. If yes, the option is controlled by application.
But if we want to ensure the user access company resource via a register device, we can look into conditional access to see if ti can help.
https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview
For example, we can control Azure AD join device to access via filter for device:
https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-condition-filters-for-devices
If we want the device enroll into Intune, we can consider the option "Require device to be marked as compliant"
https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-grant
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.