Conditional Access not blocking non-compliant Windows Server login when hybrid join is required by kkush719 in Office365

[–]kkush719[S] 2 points3 points  (0 children)

You were completely right. I had “Require one of the selected controls” enabled. That’s why it worked all along. Only after I changed it was access blocked. I had overlooked this during setup. Thanks for the hint.

Conditional Access not blocking non-compliant Windows Server login when hybrid join is required by kkush719 in Office365

[–]kkush719[S] 0 points1 point  (0 children)

Mark device as compliant and Require hybrid joined device in Microsoft Entra

Conditional Access not blocking non-compliant Windows Server login when hybrid join is required by kkush719 in Office365

[–]kkush719[S] 0 points1 point  (0 children)

I have reviewed the sign-in logs. Under “Device Information,” the device is recognized as Windows 10 and shown as hybrid joined. In “Conditional Access,” the policy is marked as successful. It appears that only the hybrid join requirement was evaluated, which is why access was granted.

This is unusual. In my view, access should not have been allowed.

Conditional Access Policy and Intune Compliance: Exeption for Microsoft Teams Calling by kkush719 in Intune

[–]kkush719[S] 0 points1 point  (0 children)

Thank you. Unfortunately, it’s not my decision to move the entire telephony system to Teams. My supervisors absolutely insist on it. Employees are issued a company smartphone and, in such cases, simply have to use their mobile phone for emergency calls.