Conditional access to support devices enrolled on intune in another tenant

Anthony Edwards 36 Reputation points
2025-07-17T16:22:34.12+00:00

I have a predicament where my organisations (users) devices are enrolled on a Microsoft Tenant we only have limited read access to (we can see them in InTune for example only), they have been grouped together so we can request apps specific to our own devices.

Ideally in the long term we would create B2B collaboration to trust those devices automatically (used by our staff - who also have a user in each tenant) in our own tenant. However this may be some time in the works, if it gets approved.

What we want to do is lock down our own tenant for access and trust devices by intune and compliance policies but essentially have to leave the conditional access policies open to allow devices in that aren't "trusted" in. I was hoping to build a compliance policy to identify those devices specifically as trusted but beyond their device naming convention this seems to be a little tricky to achieve and when I did create a policy in report mode it was flagging user access where devices aren't attached to the sign in log.

Does anyone have an immediate thoughts on this?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.