To enforce conditional access policies, you'll need to set up a device compliance policy that checks your devices' threat level in Microsoft Defender ATP. Azure AD registered devices are not eligible for conditional access unless they are enrolled in Intune. That being said, take note of the following requirements for conditional access with Microsoft Defender ATP:
- You must have an Enterprise Mobility and Security E5 license or Microsoft 365 Enterprise E5 license.
- You must have Intune configured with Windows 10 devices joined to Azure AD.
- You must have Microsoft Defender ATP and the portal (Security Center).
Assuming you have met these requirements, you can enable conditional access by following these steps:
- Go to Microsoft Defender Security Center (securitycenter.windows.com).
- Turn on the Microsoft Intune connection (advanced...