Prerequisites to configure Entra ID conditional access
Entra ID
conditional accessPrerequisite | Description |
|---|---|
Microsoft account | Verify that you have a Microsoft account with an Intune license and with one of the following Entra ID roles (or a custom role with equivalent permissions):
|
Requirements for device users |
|
Microsoft Endpoint Manager configuration | In the Microsoft Endpoint Manager admin center, in the section for Partner Compliance Management, add BlackBerry UEM Conditional Access as a compliance partner for iOS and Android devices and assign the compliance partner configuration to users and groups. For more information, see Microsoft Intune: Support third-party device compliance partners in Intune. |
Entra ID configuration | In Entra ID , create and configure a conditional access policy and enable the option "Require device to be marked as compliant". Note that this is the only conditional access profile setting that UEM interacts with. The conditional access policy is required if you want to enforce access control based on compliance status. Without the conditional access policy, compliance is tracked but not enforced. |
After you verify the prerequisites above, follow the steps in Configure Entra ID conditional access.
- Note that the configuration steps will instruct you to enable theUEM Clientto enroll inBlackBerry Dynamicsand to install theUEM Clienton devices.
- The steps will instruct you to install theMicrosoft Authenticatorapp on users' devices before activation withUEM. If you want to delay conditional access enrollment on the device until theMicrosoft Authenticatorapp is installed (either manually by the user or deployed withUEM), you can enable the "Start Entra Conditional Access enrollment after authentication broker is installed" setting in the assignedBlackBerry Dynamicsprofile. Note that this option is not supported forAndroiddevices with the User privacy activation type (it does apply toAndroid Enterpriseuser privacy andAndroid Managementuser privacy). If enabled, after theMicrosoft Authenticatorapp is installed, the conditional access enrollment process is initiated when the user opens theUEM Client. OnAndroiddevices, if the work space is unlocked, the user will be prompted to open theUEM Clientto start the conditional access enrollment.