Exclude unregistered Android device in Intune from Conditional access policy

walid issa 45 Reputation points
2024-07-17T13:17:21.1566667+00:00

Is it possible to exclude unregistered android device from conditional access policy in Intune to allow user to login on this device without registration.

For example using request ID.

I don't want to exclude per User, I don't want users to access the accounts from all devices.

Thnaks

Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Karelpelck 710 Reputation points
    2024-07-17T14:11:36.26+00:00

    You cannot exclude one device that is unknown to the tenant (Unregistered) from Conditional Access Policies. There is no way to identify it. As soon as it is registered, you have a Device ID you can filter with. If the device is registered, that does not mean it needs to be enrolled in Intune.
    User's image

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Anonymous
    2024-07-18T01:50:35.8466667+00:00

    @walid issa Thanks for posting in our Q&A. From your description, did you mean that you don't want users access corporate data in unenrolled android devices? If there is anything misunderstanding, please correct me.

    Based on my understanding, when we select "Require device to be marked as compliant" in grant access, it will block all users access to corporate data in unenrolled devices.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.