A cloud-based identity and access management service for securing user authentication and resource access
Conditional access to support devices enrolled on intune in another tenant
I have a predicament where my organisations (users) devices are enrolled on a Microsoft Tenant we only have limited read access to (we can see them in InTune for example only), they have been grouped together so we can request apps specific to our own devices.
Ideally in the long term we would create B2B collaboration to trust those devices automatically (used by our staff - who also have a user in each tenant) in our own tenant. However this may be some time in the works, if it gets approved.
What we want to do is lock down our own tenant for access and trust devices by intune and compliance policies but essentially have to leave the conditional access policies open to allow devices in that aren't "trusted" in. I was hoping to build a compliance policy to identify those devices specifically as trusted but beyond their device naming convention this seems to be a little tricky to achieve and when I did create a policy in report mode it was flagging user access where devices aren't attached to the sign in log.
Does anyone have an immediate thoughts on this?