Grant
You can select the following options as Conditional Access grant settings, of which MFA is the most common one to use:
- Require MFA: Users must complete additional security requirements such as a phone call or text.
- Require device to be marked as compliant: Device must be Intune-compliant. If the device is non-compliant, the user will be prompted to bring the device under compliance.
- Require HAADJ device: Devices must be HAADJ to get access.
- Require approved client app: Device must use these approved client applications.
- Require app protection policy: The devices that you connect from must use policy-protected apps.
You could also select multiple controls, to force either multiple requirement options or one of multiple options, to provide access if multiple endpoint scenarios apply:
- Require all the selected controls
- Require one of the selected controls
Note
When selecting MFA and devices marked as compliant, you could lock yourself out...