Due to an incident (IT85607) while moving the Conditional Access policies from “Preview phase” to “general availability” in Azure Active Directory, the Conditional Access policies in Microsoft Intune might be disabled.
Since the two are basically the same you need to check your Conditional Access policies are still configured correctly.
So go to either Microsoft Intune or Azure Active Directory to check if you Conditional Access is still configured.
Follow the next steps to verify the settings in Azure AD. (steps provided in the incident portal)
- Log in to the Azure console as an Administrator
- Select Active Directory
- Select your directory
- Select Applications
- Select Office 365 SharePoint Online or Office 365 Exchange Online, depending on whether you had previously setup conditional access for these services. If you had set up conditional access for both services, choose one of them and then repeat for the other service.
- Select Configure
- Scroll to the “device based access rules” section
- Set Enable Access Rules to On
- Verify that the other settings are configured as expected
- If applicable, repeat this process for the other service (Office 365 SharePoint Online, Office 365 Exchange Online) starting at step 6.
- Verify that Conditional Access is being enforced by testing from a mobile device or PC
If you normally configure conditional access through the Intune Console use the following steps:
- Login to Intune as an Administrator
- Click on the Policy button
- Select Conditional Access
- Select SharePoint Online Policy or Exchange Online Policy, depending on whether you had previously setup conditional access for these services. If you had set up conditional access for both services, choose one of them and then repeat for the other service.
- Select “Enable conditional access policy”
- Verify that the other settings are configured as expected
- If applicable, repeat this process for the other service (SharePoint Online Policy or Exchange Online Policy) starting at step 5.
- Verify that Conditional Access is being enforced by testing from a mobile device or PC`
After changing the settings in either location, both should be the same;
Be sure to regularly check the health status of the Intune service via https://portal.office.com/adminportal/home#/servicestatus
Till next time!