How to exclude Android devices from a Microsoft Conditional Access policy?

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) allow you to secure access to your organization’s resources by enforcing specific compliance and authentication rules. However, excluding dedicated Android devices is helpful for continuously running applications such as meeting room door displays, where continuous re-authentication would disrupt standard operations. This guide walks you through excluding Android devices from your Conditional Access policies, ensuring your dedicated Android hardware remains connected without compromising overall tenant security.

Step 1: Create a New Policy in Microsoft Entra Admin Center

  1. Go to the Microsoft Entra admin center and navigate to Protection > Conditional Access > Policies.
  2. Click + New policy from the top menu bar.
  3. Enter a descriptive Name for your policy (for example, Require Compliance – Exclude Android Displays).

Step 2: Exclude Android Devices Under Conditions

  1. Under Conditions, click Exclude filtered devices.
  2. Set Configure to Yes.
  3. Select Exclude filtered devices from policy.
  4. Set up your filter rule based on your device properties:
    • Property: Select model, deviceOwnership, or displayName.
    • Operator: Select Equals or StartsWith.
    • Value: Enter the target value.
  5. Click Done and save your policy changes.

Step 3: Grant Controls

  1. Under Access controls, click Grant.
  2. Select your desired enforcement rule, such as Require multifactor authentication or Require device to be marked as compliant.

Step 4: Enable Policy

  1. At the bottom under Enable policy:
  2. Set it to Report-only first to test the impact without disrupting users.
  3. Click Save to save the policy.

Leave a Comment

 

Your email is safe with us.
*
*