Microsoft Defender for Cloud Apps
Identity protection

Identity-managed devices with Conditional Access app control | Microsoft Defender for Cloud Apps

In brief

The article now distinguishes Microsoft Entra device conditions from client-certificate options and specifies uploading root or intermediate CA certificates before creating policies based on Device tag or Valid client certificate.

What Defender admins need to know

Administrators can use the clarified guidance to select the appropriate device condition and certificate type when configuring access and session policies.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Identity-managed devices with Conditional Access app control

You might wantThis article explains how to add conditions to your policy about whether a device is managed or not. To identify the state of a device, configure Conditional Access app control access and session policies to check for specific conditions, depending on whetherthat use device-management signals. If you have Microsoft Entra, you can use Intune-compliant or Microsoft Entra or not.hybrid joined device conditions. If you don't have Microsoft Entra, you can use client certificates to identify managed devices.

Check for device management with Microsoft Entra

Make sure that the client certificate is installed in the user store and not the computer store. You then use the presence of those certificates to set access and session policies.

Once the root or intermediate CA certificate is uploaded and a relevant policy is configured, when an applicable session traverses Defender for Cloud Apps and Conditional Access app control, Defender for Cloud Apps requests the browser to present the SSL/TLS client certificates. The browser serves the SSL/TLS client certificates that are installed with a private key. A certificate and its private key are typically packaged by using the PKCS #12 file format, such as .p12 or .pfx.

When a client certificate check is performed, Defender for Cloud Apps checks for the following conditions:

Upload your root or intermediate CA certificates to Defender for Cloud Apps in the Settings > Cloud Apps > Conditional Access App Control > Device identification page.

After the root or intermediate CA certificates are uploaded, you can create access and session policies based on Device tag and Valid client certificate.

To test client certificate-based device identification, use our sample root CA and client certificate, as follows: