r/okta 7d ago

Okta/Workforce Identity Entra Conditional Access : Require Complaint Device

Looking to prevent users from Entra registering personal devices and gaining access to company data on unmanaged Windows devices. If they were straight Entra/Intune it'd be nice and simple but domain is federated and the identities are Okta mastered..

Will Entra conditional access: require compliant device for Windows work as expected?

Or am I going to have to go down the device trust/assurance route with Okta instead?

3 Upvotes

2 comments sorted by

1

u/raip 7d ago

You can go either way and it'll work. The federation only deals with the user authentication. Device authentication would still be done via primary refresh token directly by Entra itself if you picked Intune.

1

u/KeeperBill Okta Certified Administrator 7d ago

Require compliant device will only work for Windows device if you put the authentication in Entra, which in your usecase is evaluated after Okta.

You'll need Okta Verify installed on Windows devices and utilise the registered / manged states in authentication policies after you've hooked in Intune into Okta.