Skip to content
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies

Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies

Written By Anoop C Nair
Last Updated August 9, 2024
Posted In Intune
SHARE

Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment? Windows 10 conditional access is an excellent feature for BYOD scenarios. We wanted to provide BYOD users with an OOBE (Out Of Box Experience) with AAD join and Intune auto-enrollment.

Once the user can log in with their cooperate credentials (using AAD login) to the brand new device, which is not joined to on-prem AD, the device is a complaint as per corp security policies. The user should allow access to corps mail without any blockage (or without any VPN connection).

We struggled to get this working for Windows 10 RTM version 10240. Conditional access didn’t work with the RTM version of Windows 10, but It worked well with Windows 10 versions 10175 and TH2 10586.

We tested Windows 10 conditional access with different AAD + MDM (Intune) join scenarios. From the tenant side (Intune console), we enabled Conditional Access for Exchange online, as noted in the screenshot below.

Patch My PC

Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies

Discuss the Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies. More details about Azure AD Join here (Azure AD Join: What happens behind the scenes?).

Windows 10-Conditional Access-AAD-MDM-7 Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies – Fig.1

We wanted to give BYOD users an OOBE (Out Of Box Experience) with AAD join and Intune enrollment. Once the users can log in with their cooperate credentials and the device is a complaint, they should be able to access corps data/mail without any blockage.

Choose How You Will Connect
Join Azure AD
Join a Domain
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies – Table 1
Windows 10-Conditional Access-AAD-MDM-1 Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies – Fig.2

We can confirm whether the device has successfully joined AAD and is enrolled in MDM (Intune) by checking the work access option on the Windows 10 device’s settings page.

Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies - Fig.3
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies – Fig.3

We must ensure compliance policies are applied to the Windows 10 device to secure corporate environment data. Once Intune tries to apply compliance policies on the device, we will get a popup stating that we need to enforce these policies. We may get mail access once MDM (Intune) policies are applied to the Windows 10 device.

Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies - Fig.4
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies – Fig.4

When using Office 2013 on a Windows 10 machine for conditional access, you need to enable modern authentication for Outlook. We must do this using the registry keys mentioned in the following document.

Modern authentication is also enabled for Office 2016 (Outlook 2016), so conditional access for Windows 10 with AAD and Intune will work seamlessly for the Office 2016 version.

Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies - Fig.5
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies – Fig.5

When you use a native mail application (of Windows 10) for corporate mail access, you don’t need to make any unique settings. The default mail app in Windows 10 will work with conditional access.

Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies - Fig.6
Windows 10 Conditional Access with Azure AD Join Intune MDM Auto Enrollment Enforce Policies – Fig.6

Resources

Learn Microsoft Intune Related Posts Real World Experiences (anoopcnair.com)

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 2 comments

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read