question

danaman avatar image
0 Votes"
danaman asked LuDaiMSFT-0289 commented

Intune Android Enterprise MFA

Hi

When we initially migrated from Android Device Administrator to Android Enterprise we came across an issue with user enrolment in fully managed mode.

If the device the user had just factory reset was the same device they previously used for MFA then they could not complete MFA on said device (too early in device boot process to receive a text or an app prompt)

Microsoft gave us two options at that point

  1. Exclude the user from MFA during enrolment.

  2. Ask the user to MFA using an alternative device

We chose option 1 and excluded users from our current CA policy during enrolment.

This CA policy provides to controls

MFA required
Require device to be marked as compliant.

We were not too concerned about the device compliance as if a device was non compliant removing the user from the CA exclusion would ensure the device would have to be made compliant or users would lose access to company resources.

This was never an ideal situation but its what we had at the time.

Microsoft have attempted to address this situation by adding suggesting that we exclude the following cloud app from the CA policy 'intune enrolment'

I tested this and I still faced an MFA prompt during enrolment. I confirmed using whatif that no other CA policy was in affect for my user account. I did some technet deep diving and found that other users has experienced the same issue recently. They have been advised that they now need to exclude both 'Intune' AND 'Intune Enrolment' so that users can enrol without any MFA prompt.

I tested this and it works.

With our current CA policy granting both device marked as compliant and MFA then excluding 'Intune' from this does this mean this CA policy will no longer mark our devices as uncompliant and block access to resourced because we are excluding the cloud service 'intune'?






mem-intune-enrollment
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LuDaiMSFT-0289 avatar image
0 Votes"
LuDaiMSFT-0289 answered

@danaman Thanks for posting in our Q&A.

Based on my understanding, intune evaluates whether the device is compliance, rather than CA. For this issue, I have done some research. I find that a device can't be evaluated for compliance until it's enrolled.

On the other hand, if we select "Require device to be marked as compliant" for All users and All cloud apps, it will trigger device enrollment. We can read the following article as a reference.
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-compliant-device#create-a-conditional-access-policy

In conclusion, access to resources depends on whether the device is compliant in intune.

Hope the above information will help.


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

PaD-7009 avatar image
0 Votes"
PaD-7009 answered

As long as you have O365 & SharePoint apps selected in CA, it is going to check the device compliance. So to answer your question, Azure CA policy will block if the device is non-compliant, even though you have excluded Intune from CA policy.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

danaman avatar image
0 Votes"
danaman answered LuDaiMSFT-0289 commented


So if we exclude both Intune and Intune Enrolment from our CA policy which grants both MFA and device marked as compliant then if the device is non compliant our CA policy will still block access to company resources.

That is what I wanted to hear thank you both :)

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@danaman You're welcome. If you have any problem in the future, welcome to post in our Q&A.

Thanks and have a nice day. : )

0 Votes 0 ·