Learn about using Conditional Access
By using Intune or Configuration Manager, you help ensure your organization is using proper credentials to access and share company data.
Conditional Access with Intune
Intune provides the following types of Conditional Access:
- Device-based Conditional Access
- Conditional Access for Exchange on-premises
- Conditional Access based on network access control
- Conditional Access based on device risk
- Conditional Access for Windows PCs
- Corporate-owned
- Bring your own device (BYOD)
- App-based Conditional Access
Conditional Access using co-management
With co-management, Intune evaluates every device in your network to determine how trustworthy it is. It does this evaluation in the following two ways:
- Intune makes sure a device or app is managed and securely configured. This check depends on how you set your organization’s compliance policies. For example, make sure all devices have encryption enabled and aren’t jailbroken.
- This evaluation is pre-security breach and configuration-based.
- For co-managed devices, Configuration Manager also does configuration-based evaluation for things like required updates or apps compliance. Intune combines this evaluation along with its own assessment.
- Intune detects active security incidents on a device. It uses the intelligent security of Microsoft Defender for Endpoint (formerly Microsoft Defender Advanced Threat Protection or Windows Defender ATP) and other mobile threat-defense providers. These partners run ongoing behavioral analysis on devices. This analysis detects active incidents, then passes this information to Intune for real-time compliance evaluation.
- This evaluation is post-security breach and incident-based.