{"id":73427,"date":"2026-08-05T22:33:57","date_gmt":"2026-08-05T20:33:57","guid":{"rendered":"http:\/\/adiumento.local\/?page_id=73427"},"modified":"2026-08-05T22:33:57","modified_gmt":"2026-08-05T20:33:57","slug":"entra-intune-conditional-access-compliance","status":"publish","type":"page","link":"https:\/\/adiumento.de\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-microsoft-umgebung\/entra-intune-conditional-access-compliance\/","title":{"rendered":"Entra ID, Conditional Access, Intune and device compliance"},"content":{"rendered":"<div class=\"wp-block-cover alignfull is-position-center-left service-page-hero is-light alignfull\" style=\"min-height:420px;aspect-ratio:unset;\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" class=\"wp-block-cover__image-background wp-image-73456\" alt=\"Sichere Microsoft-Umgebung\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft.png\" data-object-fit=\"cover\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><span aria-hidden=\"true\" class=\"wp-block-cover__background has-dark-background-color has-background-dim-50 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container\"><p class=\"service-page-back is-layout-flow wp-block-cover-is-layout-flow\"><a href=\"https:\/\/adiumento.de\/en\/?page_id=73415\">\u2190 Secure Microsoft environment<\/a><\/p><h1 class=\"wp-block-heading\">Entra ID, Conditional Access, Intune and device compliance<\/h1><p class=\"has-medium-font-size wp-block-paragraph\"><strong>Connect identity, access and device health into an operable zero-trust chain.<\/strong><\/p><\/div><\/div>\n\n\n\n<div class=\"wp-block-group is-style-section-light service-page-orientation adiumento-passage is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-orientation__text wp-block-paragraph\">Microsoft Entra ID, Conditional Access, and Intune work together when Intune evaluates device health against defined rules, reports that status to Entra ID, and Conditional Access uses it to make access decisions. Security is not created through individual guidelines, but rather through a coordinated governance, rollout and exception process. This is the only way access decisions remain comprehensible and the company remains able to act.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Relationship to services and technologies<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft.png\" alt=\"Sichere Microsoft-Umgebung\" class=\"wp-image-73456 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-microsoft-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">The page describes the control logic between identity, device status and access. Product details and how to order endpoint or zero trust implementation can be found at <a href=\"https:\/\/adiumento.de\/en\/technologien\/\">Technologies<\/a> and <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">Solutions<\/a>.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Background<\/h2>\n\n<p class=\"wp-block-paragraph\">Cloud services, hybrid devices and remote work are dissolving the previous assumption that network location establishes trust. At the same time, unclear groups, unmanaged devices, perpetual exceptions, or overlapping policies lead to outages and difficult-to-explain access. The central question is therefore: Which identity is allowed to access which resource under which device, risk and context status?<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Technical context<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7.png\" alt=\"Abstrakte Illustration: Threat Detection und Schutzschild in Blau.\" class=\"wp-image-73233 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Intune compliance policies assess platform-specific rules, such as operating system level, encryption, or health status, and report compliance status to Entra ID. Conditional Access can be used with the access condition <strong>Require device to be marked as compliant<\/strong> then allow or block resources. Compliance is a signal, not a complete security judgment: assessment depends on platform, check-in, policy assignment, and how unassigned devices are handled. Depending on the platform, Intune actions can flag devices as non-compliant, request a remediation, or restrict access via Conditional Access; \u201cRemediated\u201d and \u201cquarantined\u201d are not uniform effects across all platforms.<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This interaction fleshes out Zero Trust as an architectural and operating principle: trust is continually assessed based on identity, device, context and resource. It is not a product condition and is not a replacement for ADIUMENTO's existing product and service pages.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">What companies need to clarify specifically<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Protection goals and resource segments: Which applications need which access conditions?<\/li>\n<li>Identity and Group Model: Who approves memberships, privileged roles, and emergency accounts?<\/li>\n<li>Device classes: Enterprise device, BYOD, special device, shared device, and unmanaged exceptions.<\/li>\n<li>Compliance baseline and consequences: Which rule is mandatory, when is a device marked as non-compliant, required to be remedied, or access restricted?<\/li>\n<li>Exception process: purpose, approval, technical scope, expiration date and review.<\/li>\n<\/ul>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">From requirements to implementation<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1344\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7.png\" alt=\"Abstrakte Illustration: Cloud-Infrastruktur und Plattformen in Blau.\" class=\"wp-image-73218 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7.png 1344w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-300x171.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-1024x585.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-768x439.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-18x10.png 18w\" sizes=\"auto, (max-width: 1344px) 100vw, 1344px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Control access in a context-related manner<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Access from inappropriate devices<br><strong>Organisational measure:<\/strong> Define protection classes<br><strong>Technical implementation:<\/strong> CA by user, resource and device<br><strong>Possible evidence:<\/strong> Policy Export, Release<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Evaluate device condition<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Inconsistent baselines<br><strong>Organisational measure:<\/strong> Define platform responsibility<br><strong>Technical implementation:<\/strong> Intune Compliance Policies<br><strong>Possible evidence:<\/strong> Compliance report<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Limiting exceptions<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Permanent bypass<br><strong>Organisational measure:<\/strong> Process and review make binding<br><strong>Technical implementation:<\/strong> Exclusion groups with owners<br><strong>Possible evidence:<\/strong> Exception register<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Roll out changes safely<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Service interruption<br><strong>Organisational measure:<\/strong> Pilot and rollback plan<br><strong>Technical implementation:<\/strong> Report-only, test groups, staggered rollout<br><strong>Possible evidence:<\/strong> Change and test results<\/p><\/details>\n<\/div>\n\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Working with ADIUMENTO<\/h2>\n\n<p class=\"wp-block-paragraph\">This specialist page describes the control logic, not an independent service offer. Existing Endpoint Management and Zero Trust offerings are over <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">Endpoint Management<\/a>, <a href=\"https:\/\/adiumento.de\/en\/leistungen\/\">Services<\/a> and <a href=\"https:\/\/adiumento.de\/en\/technologien\/\">Technologies<\/a> reachable.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Typical Results<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-intune-endpoint-1.png\" alt=\"Abstrakte Illustration: Endger\u00e4te-Management und Richtlinien in Blau.\" class=\"wp-image-73232 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-intune-endpoint-1.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-intune-endpoint-1-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-intune-endpoint-1-768x576.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li>Access matrix and aligned device categories;<\/li>\n<li>documented compliance baseline with allocation and exception principles;<\/li>\n<li>staggered conditional access rollout including emergency access;<\/li>\n<li>Control and operational evidence for policies, status and changes.<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Limitations and dependencies<\/h2>\n\n<p class=\"wp-block-paragraph\">A \u201ccompliant\u201d status is time-dependent and does not mean a promise of conformity or complete freedom from compromise. Licensing, platform support, Entra enrollment, Intune check-ins, and clean identity credentials are prerequisites. ADIUMENTO does not provide legal advice and does not guarantee compliance.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Further official sources<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-endpoint-cloud-security-2.png\" alt=\"Abstrakte Illustration: Endpoint-Schutz und Cloud-Policies in Blau.\" class=\"wp-image-73238 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-endpoint-cloud-security-2.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-endpoint-cloud-security-2-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-endpoint-cloud-security-2-768x576.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/overview\">Microsoft Entra Conditional Access<\/a> \u2013 Microsoft Learn<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/plan-conditional-access\">Plan Conditional Access<\/a> \u2013 Microsoft Learn<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/intune\/intune-service\/protect\/device-compliance-get-started\">Intune device compliance<\/a> \u2013 Microsoft Learn<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/zero-trust\/\">Zero Trust guidance<\/a> \u2013 Microsoft Learn<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light service-page-topics adiumento-passage adiumento-themen-faq is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-section-kicker wp-block-paragraph\">Orientation<\/p>\n<h2 class=\"wp-block-heading has-text-align-center\">Frequently asked questions<\/h2>\n\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Should devices without an assigned compliance policy be considered compliant?<\/summary><p class=\"wp-block-paragraph\">Microsoft notes that the tenant setting for this can be \u201cCompliant\u201d by default. If compliance results are used for conditional access, the setting should be consciously evaluated; \u201cNot compliant\u201d ensures that only confirmed devices receive the status.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">How do we avoid a widespread lockout?<\/summary><p class=\"wp-block-paragraph\">With documented emergency access accounts, clear exclusion governance, test groups, report-only phases and a tested fallback procedure. Exceptions must not become permanent shadow architecture.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">What happens after unauthorized access or a security incident?<\/summary><p class=\"wp-block-paragraph\">The identity and device signals must transition into a process chain of detection, triage, containment and learning. This chain treats <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-microsoft-umgebung\/defender-wdac-monitoring-incident-response\/\">Defender, app control, monitoring and incident response<\/a>.<\/p><\/details>\n<\/div>\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Next sensible step<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1344\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7.png\" alt=\"Abstrakte Illustration: Cloud-Infrastruktur und Plattformen in Blau.\" class=\"wp-image-73218 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7.png 1344w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-300x171.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-1024x585.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-768x439.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hero-7-18x10.png 18w\" sizes=\"auto, (max-width: 1344px) 100vw, 1344px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Start with a delineated resource group and a device class. Microsoft recommends emergency access accounts, report-only, pilot groups, and a phased rollout for Conditional Access. To transition to a confirmed offer: <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">Endpoint Management<\/a>.<\/p>\n<\/div><\/div>\n\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Connect Entra ID, Conditional Access and Intune as a controllable zero-trust chain: governance, rollout, exceptions, evidence and operations.<\/p>","protected":false},"author":3,"featured_media":0,"parent":73415,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-73427","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/comments?post=73427"}],"version-history":[{"count":4,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73427\/revisions"}],"predecessor-version":[{"id":73513,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73427\/revisions\/73513"}],"up":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73415"}],"wp:attachment":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/media?parent=73427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}