Device Compliance / Conditional Access on Shared machines

Jordan Gibbs 0 Reputation points
2023-04-11T08:25:35.8166667+00:00

Hello I am investigating and trying to impliment my companies Device Compliance & Conditional Access policies onto multi-user ( shared user account ) machines. Hybrid Azure environment with Seamless SSO enabled To describe the setup in a short summary, we have Conditional Access setup so users can access company resources ONLY when they are connecting from a Compliant device. The compliancy rules are that it is enrolled / is an active user / av up to date and a couple of others that aren't important. For users that have their own dedicated machine this works correctly, they log into the device and can access Outlook , One Drive etc fine . They sign into Edge and the Device ID is passed through so they can access everything online too. However, for these 'Shared' machines I can't seem to get the configuration correct. These are configured by having a main Windows log in ( with E3 and EMS license ) then 3 or 4 users with P1 licenses can go to the web to access emails and sharepoint. I have tried multiple configuration policies in an attempt to get the Shared user account to be compliant, which allows the multiple P1 users to sign into Office 365 on the web. My main stumbling blocks are : 1 . Without EDGE being signed in, the DEVICE ID is not passed through when users try to access office.com ( for example ) resulting in the device not being compliant and users not being able to access resources. 2. When EDGE is signed in as the WINDOWS user, EDGE automatically signs into everything office related ( due to SSSO ) which results in the same, no reliable / continued access to resources. 3. I also can't seem to find any information on how to raise a ticket with Microsoft regarding this ( without going through our reseller ) AND information on buying a one off support ticket. Any help will be much appreciated

Microsoft Edge
Microsoft Edge
A Microsoft cross-platform web browser that provides privacy, learning, and accessibility tools.
2,223 questions
Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,063 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
144 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,351 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2023-04-12T00:54:43.0666667+00:00

    @Jordan Gibbs, Thanks for posting in Q&A.

    Based as I know, for shared device, the enrolled user is empty. So the "Enrolled user exists" will show not compliant. This is by design. For your situation, I think we can configure conditional access policy to filter the shared device to bypass. For example, we can use "profileType" to exclude the shared devices. Here is a link with more details for your reference:

    https://video2.skills-academy.com/en-us/azure/active-directory/conditional-access/concept-condition-filters-for-devices#supported-operators-and-device-properties-for-filters

    Meanwhile, I notice you want to open case. Here is a link with the steps to open Intune case for your reference:

    https://video2.skills-academy.com/en-us/mem/get-support

    For the pay related, you can call the Phone number in the following location to see if it can help.

    https://support.microsoft.com/en-us/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.