Skip to content
← Back to the guide

How to require compliant devices with Conditional Access

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

How to require compliant devices with Conditional Access

How to require a compliant or hybrid-joined device with Conditional Access: the Intune compliance policy first, the grant control, exclusions, report-only.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

What happens to devices with no compliance policy assigned?

By default Intune marks devices with no compliance policy as Compliant, which silently defeats this Conditional Access control. Set 'Mark devices with no compliance policy assigned as: Not compliant' under Intune → Devi…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

Will this block personal phones from reading email?

Yes, unless you give them another route. Personal mobile devices either enrol in Intune (MDM) to become compliant, or you add a second grant option — 'Require app protection policy' — so that Outlook mobile under an app…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

Does requiring a compliant device replace MFA?

No. Set both, with 'Require all the selected controls'. A compliant device proves the endpoint is managed and healthy; MFA proves the person. Attackers who steal a session token from a compliant device get past device c…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

Step 1: Create a compliance policy per platform

Intune → Devices → Compliance → Create policy. Minimum sensible Windows policy: Require BitLocker, Require Secure Boot, Require code integrity, Minimum OS version (current minus one), Microsoft Defender Antimalware on a…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Step 2: Fix the default for unassigned devices

Devices → Compliance → Compliance policy settings: Mark devices with no compliance policy assigned as: Not compliant. Leave the compliance status validity period at the default 30 days.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

Step 3: Build the Conditional Access policy in report-only

Entra → Protection → Conditional Access → New policy:

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

Step 4: Read the report-only results

A week, minimum. Sign-in logs → Conditional Access → Report-only → Failure: each row is a device that would have been blocked. Sort by user and device: unenrolled corporate laptops (enrol them), Linux (needs a decision…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-require-compliant-devices-with-conditional-access

Slide 8Download PNG

Auto-generated from How to require compliant devices with Conditional Access. This page is not indexed and isn't part of the guide itself.