Prerequisites to configure Entra ID conditional access
Entra ID
conditional access- Verify that you have aMicrosoftaccount with anIntunelicense and with one of the following permissions in theEntraportal: global administrator, limited administrator with the Intune Service administrator role, or a custom role with the permissions described in KB 50341.
- In theMicrosoftEndpoint Manager admin center, in the section for Partner Compliance Management, addBlackBerry UEM Entra Conditional Accessas a compliance partner foriOSandAndroiddevices and assign it to users and groups.
- InEntra ID, create and configure a conditional access profile and enable the option "Require device to be marked as compliant". Note that this is the only conditional access profile setting thatUEMinteracts with.
- To use this feature, device users must meet the following requirements:
- Users must exist inEntra IDand must have a validIntunelicense. For more information, see Microsoft Intune licenses.
- If you synchronize your on-premisesActive DirectorywithEntra ID, users’ on-premisesActive DirectoryUPN must match theirEntra IDUPN.
- Users must be added toUEMas directory users.
- After you verify the prerequisites above, follow the steps in Configure Entra ID conditional access.
- Note that the configuration steps will instruct you to enable theUEM Clientto enroll inBlackBerry Dynamicsand to install theUEM Clienton devices.
- The steps will instruct you to install theMicrosoft Authenticatorapp on users' devices before activation withUEM. If you want to delay conditional access enrollment on the device until theMicrosoft Authenticatorapp is installed (either manually by the user or deployed withUEM), you can enable the "Start conditional access enrollment after authentication broker is installed" setting in the assignedBlackBerry Dynamicsprofile. Note that this option is not supported forAndroiddevices with the User privacy activation type (it does apply toAndroid Enterpriseuser privacy andAndroid Managementuser privacy). If enabled, after theMicrosoft Authenticatorapp is installed, the conditional access enrollment process is initiated when the user opens theUEM Client. OnAndroiddevices, if the work space is unlocked, the user will be prompted to open theUEM Clientto start the conditional access enrollment.