DV-02Easy

How to Fix: Require Compliant Devices for Global Admins

Step-by-step guide to implement require compliant devices for global admins in your Microsoft 365 environment.

5-10 minutes

Estimated Time

4

Steps

critical

Severity

Enhanced Security

Baseline Level

Why This Matters

Admin credentials on non-compliant devices are at high risk. Keyloggers, malware, and credential theft are common on unmanaged devices. Requiring compliance ensures admin actions occur from secured endpoints.

Prerequisites

  • 1Global Administrator or appropriate admin role in Microsoft Entra ID
  • 2Access to Microsoft Entra admin center (entra.microsoft.com)
  • 3Microsoft Entra ID P1 or higher license
  • 4Conditional Access Administrator role (minimum)

Expected Configuration

  • All Global Administrator sign-ins require compliant devices
  • Devices are enrolled in Intune with compliance policies
  • Non-compliant devices cannot access admin portals

Remediation Steps

1

Review Existing Policies

Examine your current Conditional Access policies.

  • Navigate to Microsoft Entra admin center
  • Go to Protection > Conditional Access
  • Review existing policies and their configurations
2

Design Policy Configuration

Plan the Conditional Access policy that addresses this control.

  • Define target users and groups
  • Determine target applications
  • Plan grant and session controls
3

Create or Update Policy

Implement the Conditional Access policy.

  • Create new policy or modify existing one
  • Configure assignments (users, apps, conditions)
  • Set appropriate grant and session controls
  • Start in Report-only mode for testing
4

Test and Enable

Validate the policy works correctly before full enforcement.

  • Monitor Report-only results
  • Test with pilot group
  • Switch to On when confident
  • Run TrueConfig scan to verify compliance

Auto-Remediation Available

TrueConfig can automatically fix this control for you. Enable auto-remediation to have this configuration applied and maintained automatically.

Learn about auto-remediation

Related Resources

Automate Your Security Configuration

TrueConfig continuously monitors your Microsoft 365 environment and can automatically fix configuration drift. Start your free trial today.

Start Free Trial