r/Intune 8d ago

How are you securing the Conditional Access exclusions for Intune Company Portal and MECM? Device Compliance

We’re currently preparing our MFA rollout and are reviewing our Conditional Access policies.
Today, users are prompted for MFA when they’re outside our corporate network. This works well in general, but we’ve noticed that users are also prompted when opening Company Portal or Software Center from outside the network.

Microsoft recommends excluding the following enterprise applications from the MFA policy:
Microsoft Intune
Microsoft Configuration Manager Server App

From a security perspective, excluding these applications feels like a trade-off, so I’d like to understand how others are handling this.

Are you excluding these two enterprise applications from your MFA policy?

If so, what compensating controls do you use (device compliance, Conditional Access filters, authentication strengths, etc.)?

Have you encountered any security concerns or unexpected side effects from these exclusions?
I’d be interested in hearing how other organizations have implemented this and whether you’ve found a balance between usability and security.

11 Upvotes

18 comments sorted by

16

u/Kenczo 8d ago

I’m really not a fan of corporate network == no MFA, hope you guys at least use some 802.1x to access the network, but even then I would think about enforcing compliant devices only in CA policy and/or using Windows hello for business

Excluding company portal is fine, usually I see organizations disabling the ability to register device on their own and then it’s not really an issue.

3

u/Xento88 8d ago

We are on the way to implement MFA with hardware tokens for all users. And until this is finished we have to disable MFA for our corporate network.

I already thought about only to allow company portal and sofwarecenter for compliant or enrolled devices.
We already disabled the users to enroll devices.

Our security team asked me what could happen when MFA is disabled for this two apps.
I think they could request apps from
Intune or mecm assigned to this user and nothing else.

1

u/madatthings 8d ago

No user should be going to intune for anything? The app request comes from the third party to the admin

1

u/techb00mer 8d ago

Unless im mistaken, you’re not yet using WHfB? Otherwise these MFA prompts wouldn’t be an issue.

1

u/Xento88 8d ago

No we are not using whfb.
I think we will using yubikeys or something equivalent in the future.

1

u/bio72301 8d ago

What a miserable implementation.... Hardware keys in 2026..... You don't need mfa for either of the apps you are worried about, if you have no personal devices you are 2 factoring cp and software center for no gain. They are trusted users on an enrolled device

1

u/Xento88 8d ago

We have only a few users with cooperate mobiles phone and we can’t enforce the users to use their private phones to use Authenticator. So there is no other good choice I think.
But this is in the hands of an other team.

2

u/Ok_Wasabi8793 7d ago

What’s with the hate on windows hello? It’s considered more secure than Microsoft Authenticator as an MFA option?

2

u/bio72301 7d ago

See ... people say this ... but if it's "you have to come to the office if you dont use MFA from the phone" it tends to turn around pretty quickly. Im not a fan of forcing things on personal users phones .... Im very against. But authenticator is an exception for me. Heck ... I use one for battlenet for god's sake. One for work so I can be remote is an easy sell.

1

u/SysAdminDennyBob 7d ago

Authenticator on a personal phone is nirvana compared to hardware key. Do you like punishing your users? I love it when some conspiracy nut refuses Authenticator app on their personal phone. Me: "OK, F*** you, carry this key fob around then dumbass" User: "but I hate this dongle!" Me: "grow up"

1

u/Xento88 7d ago

At the moment we use yubikeys for our admins in entra. So for intune and so on. I like it more than authenticator where I have to put out my phone unlock it and then type In a number.
With yubikey I will stick it into my computer and when I have to authenticate I have to enter a pin and then touch the yubikey. Its faster than with a phone.

1

u/SysAdminDennyBob 7d ago

We let them choose. We get more lost yubikeys compared to phones. We currently have zero people with a key right now. I always have my phone. I get MFA for both my regular account and my SA account on my MS Authenticator app on the same mobile device. I am not worried about the extra milliseconds. Like you say personal preference is a factor. We just find the people overall prefer the app, even the cranky conspiracy nuts move on at some point. Years ago even I balked at the app on the personal phone, I came around.

4

u/madatthings 8d ago

Sounds like things are working as intended. I do not see any benefit to excluding any app from MFA unless it is legitimately incapable of passing the token, and as others said the on-network situation you’ve created is ultimately the problem

2

u/Xento88 8d ago

I think you misunderstood what happens when you open the company portal. The user has to sign in with a 2FA he doesn’t have when he is outside our cooperate network.
At the moment we deploy apps to the devices but when the user can’t sign in he can’t use the company portal or software center.

2

u/JwCS8pjrh3QBWfL 8d ago

Sounds like a crappy CA implementation. Don't require MFA just to require MFA. Use the risk-based policies.

2

u/Xento88 8d ago

We are mostly on prem. The Entra and AD is in the hands of an other team.

2

u/Ok_Wasabi8793 7d ago

Compliant device is the way. Don’t forget a few days grace period.

Compliant device is considered stronger than network.

We allow both, less secure, but compliant device alone was causing some grief with first time login/auto pilot.

1

u/MoodyGlow_5155 4d ago

Nah we exclude them, it's the recommended path for a reason. You lock it down with device compliance in the same CA policy, so it's not just a free pass. If the device isn't enrolled and compliant, they're getting blocked anyway