The modern security perimeter now extends beyond an organization's network to include user and device identity. Organizations can utilize these identity signals as part of their access control decisions.

Conditional Access is the tool used by Azure Active Directory to bring signals together, make decisions, and enforce organizational policies. Conditional Access is at the heart of the new identity-driven control plane.

This document explains the configuration steps to create a policy that blocks access to Microsoft 365 resources from unmanaged or Non-Compliant devices.

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

Note
If the policy needs to be applied for any specific Microsoft 365 service, we can select “Select Apps” and select the apps from the list.

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

User Experience

Block Access to Microsoft 365 Resources from Unmanaged Windows Device

Once the user tries to login from an unmanaged or Non-Compliant device, the user receives an error message as above.

“Based on the Browser the error message will vary, but the result will be same”.