To restrict Microsoft 365 access to compliant corporate devices, enroll the intended endpoints in Microsoft Intune, assign compliance policies, then create a Microsoft Entra Conditional Access policy that requires devices to be marked compliant. Start the policy in report-only mode, review its sign-in impact, exclude emergency access accounts, and enforce it only after confirming the scope and expected results.
How the device-compliance check works
Intune compliance policies evaluate managed devices against requirements your organization defines. Intune reports each device’s compliance status to Microsoft Entra ID, and Conditional Access can use that status to allow or block access to selected resources. The compliant-device grant is a status check—not a purchase check or proof of ownership. Microsoft’s setup guidance and its device-based Conditional Access overview describe this integration.
The device needs to be enrolled in Intune and have a compliance policy assigned for the status check to work as intended. Requiring compliance does not itself block Intune enrollment; manage who may enroll devices separately. Intune’s compliance-policy documentation covers policy creation and supported platform categories.
Plan the boundary before creating a policy
Choose who and what the policy covers
Decide which users or groups and which resources the rule should apply to. Also determine the platforms and client app types you intend to cover, and test those combinations in your tenant. The cited Microsoft guidance does not establish that one policy behaves identically for every Microsoft 365 workload, browser, legacy authentication path, or client version. Avoid assuming that one rule blocks every possible sign-in route.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
- Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
- 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
- Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
- Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.
Define what counts as corporate
Set a separate organizational rule for corporate ownership and enrollment. A device marked compliant is not automatically a corporate-owned device. If personal devices must not enroll, configure enrollment controls accordingly; Microsoft’s Business Premium device-management guidance discusses enrollment controls, including blocking personal devices.
Check licensing and platform support
- The cited device-based Conditional Access and Intune compliance guidance specifies Microsoft Entra ID P1 or P2 and an Intune subscription for compliance-policy management. Check current licensing documentation and the tenant’s entitlements before rollout; bundles and terms can change. See Microsoft’s device-based policy guidance and Intune’s compliance-policy documentation.
- Microsoft’s grant-control guidance lists Windows 10+, iOS, Android, macOS, and Ubuntu Linux devices registered with Microsoft Entra ID and enrolled with Intune for the compliant-device control. This does not mean every OS version or client has identical behavior. Check the current grant-control documentation for your platforms.
- Intune’s compliance-policy categories include Android Enterprise, Android AOSP, iOS, Linux, macOS, and Windows. Android device administrator management is deprecated for devices with Google Mobile Services; verify the current platform-specific requirements before assigning policies. See Intune’s platform guidance.
Prepare Intune compliance before Conditional Access
- Enroll the intended corporate endpoints in Intune. Confirm that each device type you plan to require can enroll and report its management state.
- Create and assign compliance policies for the relevant platforms. Define requirements that reflect your organization’s security baseline, then assign the policies to the users or devices that need them. The current policy workflow and platform options are in Microsoft’s Intune compliance-policy guide.
- Verify a representative device reports compliant. Check the device’s status in Intune before requiring that status for access. If the device is not compliant, investigate its assigned policy and reported status rather than proceeding as if the Conditional Access rule can supply the missing compliance configuration.
- Set the no-policy behavior deliberately. For the Business Premium scenario described by Microsoft, configure devices without an assigned compliance policy as Not compliant when the goal is to admit only devices whose compliance has been verified. See Microsoft’s setup guidance.
Create the Conditional Access policy
- In the current Microsoft Entra admin center, create a Conditional Access policy. Microsoft may change navigation labels, so use the current Conditional Access policy area rather than relying on a fixed menu path.
- Choose the users or groups and resources that match the boundary you planned. Review the assignment carefully; an overly broad or incomplete selection can block unintended users or leave intended access outside the policy.
- Under Grant, require the device to be marked as compliant. The exact control is described in Microsoft’s Conditional Access grant-control documentation.
- Exclude emergency access or break-glass accounts from policies that could lock administrators out. Keep those accounts monitored and governed under your separate emergency-access practice.
- Set the policy to report-only before enforcement. Save it and use policy impact and sign-in results to examine what would happen to users in scope.
Test in report-only mode, then enforce
Review expected and unexpected outcomes
During report-only evaluation, inspect sign-ins for users, resources, platforms, and clients in scope. Confirm that representative compliant devices would be allowed and identify sign-ins that would be blocked. Check whether any expected device lacks an assigned compliance policy or has not yet reported its status. Adjust assignments or compliance configuration based on the observed outcomes.
Rank #2
Enable the policy only after review
Once the report-only results match your intent and emergency access exclusions are in place, change the policy to enabled. Verify real sign-ins after enforcement and retain a tested way to disable or revise the policy if it blocks legitimate access.
Use filters only when their attributes are reliable
Device filters can narrow Conditional Access scope using device attributes, but attribute availability may depend on whether a device is managed, compliant, or hybrid joined. Test the filter against actual tenant device records before depending on it to include or exclude a device. Microsoft documents the condition in Filter for devices as a condition in Conditional Access policy.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
Diagnose access problems after rollout
- A corporate device is blocked: Check its Intune enrollment, assigned compliance policy, reported compliance status, and the Conditional Access sign-in result. A missing policy or unavailable status can prevent the device from satisfying the grant.
- A personal device is allowed: Recheck the users and resources covered by the policy, the device’s status, and enrollment controls. Compliance alone does not prove corporate ownership.
- A client behaves differently than expected: Verify the client app, platform, resource, and authentication route in the sign-in record. Do not infer coverage for every workload or client from a successful test of one combination.
- Many users are affected unexpectedly: Review report-only or sign-in results, policy assignments, exclusions, and compliance-policy targeting. Correct the scope or underlying assignments before broadening enforcement.
Intune provides a compliance dashboard for investigating device status. Use it together with sign-in and device records to identify whether a failure comes from enrollment, compliance evaluation, or Conditional Access scope. Reporting labels and admin-center navigation may change over time.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

