Skip to main content

πŸš¦πŸŸ’πŸ’»CA - Require Compliant Device 🍏

The Mac in the corner is not exempt from physics. Office 365 from a macOS app client only from an Intune-compliant device.

🚦Type Conditional Access🟒Action Grant, require compliantπŸ’»Target macOS devices
reference-build Β· ca-compliant-device-macosGolden Master reference
License tier
Business Premium (Entra ID P1)
Control plane
Entra Conditional Access + Intune
Scope
macOS, Office 365, app clients
Reversibility
report-only first, clean-revert

What this policy is about πŸŽβ€‹

This is the Windows compliant-device policy with a different platform box ticked, and it exists because the designer's Mac is a laptop reaching Office 365 exactly like everyone else's, and a stolen token does not care what fruit is on the lid. Reaching Office 365 from a macOS desktop or mobile client now requires an Intune-compliant device.

The one difference from Windows: there is no Hybrid Azure AD join for Macs, so the grant is compliant-only. On a Mac, "trusted" means "enrolled in Intune and passing its compliance policy", full stop.

πŸ€” Same AiTM defence, fewer excuses

The reason is identical to Windows: an adversary-in-the-middle replay of a phished token arrives from the attacker's device, which is not compliant, so it is denied. The only thing platform-specific here is the tendency to forget Macs exist in the fleet. They do, and attackers are delighted when a tenant leaves them unmanaged.

πŸ› οΈ Configuration​

Where: Entra admin center β†’ Protection β†’ Conditional Access β†’ Policies.

CA policy diagram: macOS platform, Office 365, require compliant device

SettingValue
Users, includeAll users
Users, excludeπŸ›‘οΈπŸ§‘β€πŸ’Όβ›“οΈπŸ”“πŸš¦Group - Break the Glass solution
πŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“πŸš¦Group - No compliant device required for πŸ’»πŸ users
Conditions, device platformsmacOS
Conditions, client appsMobile app and desktop clients
Target resourcesOffice 365
GrantRequire compliant device
SessionNone

As with Windows, browser access is shaped by the session policies rather than blocked here. Roll out in Report-only until Macs are enrolled and passing compliance, then enforce.

Caveats βš οΈβ€‹

Macs need a real compliance policy, not a token one. Enforcing "must be compliant" is meaningless if the macOS compliance policy checks nothing worth checking. FileVault, OS version, firewall: give the compliance verdict something to stand on before you trust it here.

No hybrid join, and that is fine. Compliant-only is the correct and only option for Macs. Do not go looking for the hybrid setting that works on Windows; it does not apply, and you do not need it.

The forgotten-Mac problem is the real risk. The most common failure is not this policy misfiring, it is a Mac that was never enrolled, quietly reaching mail on a personal device outside all of this. Inventory the Macs; an unmanaged one is this policy's blind spot.

License and reversibility. P1 plus Intune, both in Business Premium. Clean-revert, so a disabled Mac policy is the drift that lets any unmanaged Mac back to the mailbox.


A Mac reaching your mail is a managed device or it is somebody's front door. Require the first and the second stops being an option. 🍎