u/Bbrazyy

▲ 4 r/entra

GSA Private Access and Conditional Access Policy

Is it possible to require an Intune complaint device before for GSA Private access works?

I’m tasked with requiring Intune compliant devices before access to a Windows Server hosted on Azure VM is granted.

I created an CAP targeting the Microsoft managed “GSA-PrivateAccessTrafficForwardingProfile” app and the Private Access app for the target VM. I configured the Grant rule to “Require device to be marked compliant” and scoped the policy to a test account.

It doesn’t seem to be working and the sign-in logs don’t even show an authentication event for any of the target resources/apps of my CAP. I can still connect to the target VM from a test company laptop and my personal laptop (which shouldn’t be allowed)

Any advice? I’m starting to think it’s not possible and honestly I need to convince my manager to let me block all personal devices in general

reddit.com
u/Bbrazyy — 3 days ago
▲ 1 r/Intune+1 crossposts

Why can WHfB can be bypassed at the login screen?

What’s the point of WHfB if I can easily just select the “other user” option at the windows sign-in screen to bypass any PIN/Biometric requirements?

We currently use DUO for MFA and deploy the Duo Windows Logon app to our windows endpoint to provide 2FA.

Am I missing something here?

reddit.com
u/Bbrazyy — 3 months ago