Windows 10: Conditional Access within InTune/Azure

Discus and support Conditional Access within InTune/Azure in AntiVirus, Firewalls and System Security to solve the problem; I am looking to set up conditional access to only allow 'Corporate' device to access some of our cloud apps. I have set up a conditional access rule... Discussion in 'AntiVirus, Firewalls and System Security' started by Nick Pratt, May 2, 2020.

  1. Conditional Access within InTune/Azure


    I am looking to set up conditional access to only allow 'Corporate' device to access some of our cloud apps.


    I have set up a conditional access rule that by default block access to the specified apps, but have an exclusion group for all corporate devices. This group is a dynamic group 'device.deviceOwnership -eq "Company" and device.deviceOSType -contains "Windows"'


    Upon testing with a test user ,it is successfully blocking access to the apps when the machine is set as 'Personal' in InTune. However, when we change the machine to 'Corporate', it is still blocking.


    On checking the dynamic group, we can see the machine in the group, and therefore should fall under the exclusion rule.


    Any ideas. My only thought is that the exclusion rule might only work on Users and not Devices.

    :)
     
    Nick Pratt, May 2, 2020
    #1
  2. Brink Win User

    Microsoft Edge conditional access and single sign-on for iOS & Android


    Source: Microsoft Edge on iOS and Android now supports conditional access and single sign-on - Microsoft Tech Community - 476091
     
    Brink, May 2, 2020
    #2
  3. Brink Win User
    Microsoft Edge conditional access and single sign-on for iOS & Android

    Source: Microsoft Edge on iOS and Android now supports conditional access and single sign-on - Microsoft Tech Community - 476091
     
    Brink, May 2, 2020
    #3
  4. Conditional Access within InTune/Azure

    Autopilot Profiles: Azure /Intune.

    In the Microsoft Partner Center Dashboard I am able to both create and configure Autopilot profiles and (once it’s working) register devices to apply those Autopilot profiles to.



    In the Azure Intune Dashboard I am able to do the exact same functions as mentioned above in the Microsoft Partner Center by navigating:

    • Open Azure
    • Open InTune
    • Click Device Enrollment
    • Click Windows Enrollment
    • In this GUI there are options for Windows Autopilot


    The odd thing is that for the same customer I can configure Autopilot in two different places. Additionally, if I create a profile in one location, it does not propagate to the other. I can have two completely different profiles in each place.



    How is it determined which is the profile that will be used for Autopilot if I have one in each place? Is one being phased out? Thanks for any information that you can provide.

    Also, what would happen if we had a device from a completely different source than Ingram? Like we inherited a client that already had PC’s, and we wanted to onboard them with the Azure/InTune stack? Would we not be able to register
    those devices? I don’t think Ingram would interested in taking requests for devices that they didn’t even sell.

    Thank you.
     
    JohneSanchez4994, May 2, 2020
    #4
Thema:

Conditional Access within InTune/Azure

Loading...
  1. Conditional Access within InTune/Azure - Similar Threads - Conditional Access within

  2. Deploy Secfurity baselines profiles from Intune to Azure VM resources

    in Windows 10 Gaming
    Deploy Secfurity baselines profiles from Intune to Azure VM resources: Hi I would like to deploy some Security baselines to Servers in our Azure enviroments. https://answers.microsoft.com/en-us/windows/forum/all/deploy-secfurity-baselines-profiles-from-intune-to/e651ef6a-44ff-40e2-81ac-5904a6d435cf
  3. Deploy Secfurity baselines profiles from Intune to Azure VM resources

    in Windows 10 Software and Apps
    Deploy Secfurity baselines profiles from Intune to Azure VM resources: Hi I would like to deploy some Security baselines to Servers in our Azure enviroments. https://answers.microsoft.com/en-us/windows/forum/all/deploy-secfurity-baselines-profiles-from-intune-to/e651ef6a-44ff-40e2-81ac-5904a6d435cf
  4. Device shows in Intune as Azure AD Joined but MDM is NONE

    in Windows 10 Updates and Activation
    Device shows in Intune as Azure AD Joined but MDM is NONE: As in the subject. How can I add it back so it's managed by Intune?We only have Azure AD. https://answers.microsoft.com/en-us/windows/forum/all/device-shows-in-intune-as-azure-ad-joined-but-mdm/29d7c862-8154-4ae4-99cf-12e3d3ffc064
  5. Device shows in Intune as Azure AD Joined but MDM is NONE

    in Windows 10 Gaming
    Device shows in Intune as Azure AD Joined but MDM is NONE: As in the subject. How can I add it back so it's managed by Intune?We only have Azure AD. https://answers.microsoft.com/en-us/windows/forum/all/device-shows-in-intune-as-azure-ad-joined-but-mdm/29d7c862-8154-4ae4-99cf-12e3d3ffc064
  6. Device shows in Intune as Azure AD Joined but MDM is NONE

    in Windows 10 Software and Apps
    Device shows in Intune as Azure AD Joined but MDM is NONE: As in the subject. How can I add it back so it's managed by Intune?We only have Azure AD. https://answers.microsoft.com/en-us/windows/forum/all/device-shows-in-intune-as-azure-ad-joined-but-mdm/29d7c862-8154-4ae4-99cf-12e3d3ffc064
  7. Conditional access in on-prem/ADFS enviroment for windows login

    in Windows Hello & Lockscreen
    Conditional access in on-prem/ADFS enviroment for windows login: Hi!I've been searching for conditional access for the windows login. Could not find anything relevant to my case so far.AD FS relying party trust/access controll policies seems to be controlling access to applications, but I need to control windows logins.GPO require smart...
  8. Conditional access in on-prem/ADFS enviroment for windows login

    in Windows 10 Gaming
    Conditional access in on-prem/ADFS enviroment for windows login: Hi!I've been searching for conditional access for the windows login. Could not find anything relevant to my case so far.AD FS relying party trust/access controll policies seems to be controlling access to applications, but I need to control windows logins.GPO require smart...
  9. Microsoft intune and azure AD

    in Windows 10 Updates and Activation
    Microsoft intune and azure AD: Hello, my school use microsoft education and i added intune and azure AD trial versions for 1 and 3 mounths. I added my devices and configurationed shared PC policy guest account and other. So when trial version will end all my devices and settings will gone? And whats...
  10. Configuring Conditional Access Rules for spoprod-a.akamaihd.net

    in AntiVirus, Firewalls and System Security
    Configuring Conditional Access Rules for spoprod-a.akamaihd.net: We are trying to configure conditional access rules for http://spoprod-a.akamaihd.net so that our end point users can access Sharepoint and OneDrive services on our network. We need the following details for http://spoprod-a.akamaihd.net.... IP Range We understand that the...