DV-02: Require Compliant Devices for Global Admins

Frequently asked questions about implementing and managing the DV-02 security control in Microsoft 365 and Entra ID.

Q
What is DV-02 (Require Compliant Devices for Global Admins)?
A

DV-02 is a security control that admin credentials on non-compliant devices are at high risk. keyloggers, malware, and credential theft are common on unmanaged devices. requiring compliance ensures admin actions occur from secured endpoints. It requires that all global administrator sign-ins require compliant devices and devices are enrolled in intune with compliance policies, non-compliant devices cannot access admin portals.

Related controls:DV-02
Q
Why is Require Compliant Devices for Global Admins important for Microsoft 365 security?
A

Admin credentials on non-compliant devices are at high risk. Keyloggers, malware, and credential theft are common on unmanaged devices. Requiring compliance ensures admin actions occur from secured endpoints.

Related controls:DV-02
Q
How do I implement DV-02 in my tenant?
A

TrueConfig provides one-click remediation for DV-02. Creates Conditional Access policy requiring device compliance for Global Admin role

Related controls:DV-02
Q
What license do I need for DV-02?
A

This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.

Related controls:DV-02
Q
Which security baseline includes DV-02?
A

DV-02 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.

Related controls:DV-02
Q
Why is DV-02 marked as critical severity?
A

DV-02 is rated critical because failure to implement this control significantly increases the risk of security incidents. Admin credentials on non-compliant devices are at high risk. Keyloggers, malware, and credential theft are common on unmanaged devices. Requiring compliance ensures admin actions occur from secured endpoints.

Related controls:DV-02

6

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial