Azure Conditional Access - Device extensionAttributes

dridley 181 Reputation points
2022-08-25T01:15:04.417+00:00

Hi MSFT,

I am trying to get CA policies to BLOCK AAD-Registered devices that DO NOT have extensionAttribute1 set.
However, devices with extensionAttribute1 are also getting blocked as they report "No Match".

Any ideas what is going on here? I have tried 2 different tenants.

234734-image.png

234628-image.png

234629-image.png

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Answer accepted by question author
  1. Harpreet Singh Matharoo 8,416 Reputation points Microsoft Employee Moderator
    2022-08-25T09:43:39.997+00:00

    Hello @Anonymous

    Thank you for being patient while I was working on this request. I would like to confirm following points with you:

    • For Azure AD Registered Device a device filter can apply in include or exclude mode for all attributes excluding extension attributes.
    • To read extension attributes, a device should be compliant / Hybrid AAD joined / Managed by Intune.

    These details can be validated on following document and below is the table from the document which describes the same: Policy behavior with filter for devices

    234871-image.png

    I hope this helps and answers the query you have.

    ----------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.