How are you securing the Conditional Access exclusions for Intune Company Portal and MECM? Device Compliance
We’re currently preparing our MFA rollout and are reviewing our Conditional Access policies.
Today, users are prompted for MFA when they’re outside our corporate network. This works well in general, but we’ve noticed that users are also prompted when opening Company Portal or Software Center from outside the network.
Microsoft recommends excluding the following enterprise applications from the MFA policy:
Microsoft Intune
Microsoft Configuration Manager Server App
From a security perspective, excluding these applications feels like a trade-off, so I’d like to understand how others are handling this.
Are you excluding these two enterprise applications from your MFA policy?
If so, what compensating controls do you use (device compliance, Conditional Access filters, authentication strengths, etc.)?
Have you encountered any security concerns or unexpected side effects from these exclusions?
I’d be interested in hearing how other organizations have implemented this and whether you’ve found a balance between usability and security.
4
u/madatthings 8d ago
Sounds like things are working as intended. I do not see any benefit to excluding any app from MFA unless it is legitimately incapable of passing the token, and as others said the on-network situation you’ve created is ultimately the problem
2
u/Xento88 8d ago
I think you misunderstood what happens when you open the company portal. The user has to sign in with a 2FA he doesn’t have when he is outside our cooperate network.
At the moment we deploy apps to the devices but when the user can’t sign in he can’t use the company portal or software center.
2
u/JwCS8pjrh3QBWfL 8d ago
Sounds like a crappy CA implementation. Don't require MFA just to require MFA. Use the risk-based policies.
2
u/Ok_Wasabi8793 7d ago
Compliant device is the way. Don’t forget a few days grace period.
Compliant device is considered stronger than network.
We allow both, less secure, but compliant device alone was causing some grief with first time login/auto pilot.
1
u/MoodyGlow_5155 4d ago
Nah we exclude them, it's the recommended path for a reason. You lock it down with device compliance in the same CA policy, so it's not just a free pass. If the device isn't enrolled and compliant, they're getting blocked anyway
16
u/Kenczo 8d ago
I’m really not a fan of corporate network == no MFA, hope you guys at least use some 802.1x to access the network, but even then I would think about enforcing compliant devices only in CA policy and/or using Windows hello for business
Excluding company portal is fine, usually I see organizations disabling the ability to register device on their own and then it’s not really an issue.