Skip Navigation

Prerequisites to configure
Entra ID
conditional access

Prerequisite
Description
Microsoft
account
Verify that you have a
Microsoft
account with an
Intune
license and with one of the following
Entra
ID roles (or a custom role with equivalent permissions):
  • Global Administrator
  • Intune Service Administrator
Requirements for device users
  • Users must exist in
    Entra ID
    and must have a valid
    Intune
    license. For more information, see Microsoft Intune licenses.
  • If you synchronize your on-premises
    Active Directory
    with
    Entra ID
    , users’ on-premises
    Active Directory
    UPN must match their
    Entra ID
    UPN.
  • Users must be added to
    UEM
    as directory users.
    UEM
    can connect to
    Entra ID
    or
    Microsoft
    AD for the directory connection. Use
    Entra ID
    if your organization's users are cloud-only. Use AD if users are hybrid (on-premises AD synchronized to
    Entra ID
    ). In either scenario UPN alignment beween
    UEM
    and Entra ID is critical for compliance evaluation.
Microsoft
Endpoint Manager configuration
In the
Microsoft
Endpoint Manager admin center, in the section for Partner Compliance Management, add
BlackBerry UEM
Conditional Access as a compliance partner for
iOS
and
Android
devices and assign the compliance partner configuration to users and groups. For more information, see Microsoft Intune: Support third-party device compliance partners in Intune.
Entra ID
configuration
In
Entra ID
, create and configure a conditional access policy and enable the option "Require device to be marked as compliant". Note that this is the only conditional access profile setting that
UEM
interacts with. The conditional access policy is required if you want to enforce access control based on compliance status. Without the conditional access policy, compliance is tracked but not enforced.
After you verify the prerequisites above, follow the steps in Configure Entra ID conditional access.
  • Note that the configuration steps will instruct you to enable the
    UEM Client
    to enroll in
    BlackBerry Dynamics
    and to install the
    UEM Client
    on devices.
  • The steps will instruct you to install the
    Microsoft Authenticator
    app on users' devices before activation with
    UEM
    . If you want to delay conditional access enrollment on the device until the
    Microsoft Authenticator
    app is installed (either manually by the user or deployed with
    UEM
    ), you can enable the "Start Entra Conditional Access enrollment after authentication broker is installed" setting in the assigned
    BlackBerry Dynamics
    profile. Note that this option is not supported for
    Android
    devices with the User privacy activation type (it does apply to
    Android Enterprise
    user privacy and
    Android Management
    user privacy). If enabled, after the
    Microsoft Authenticator
    app is installed, the conditional access enrollment process is initiated when the user opens the
    UEM Client
    . On
    Android
    devices, if the work space is unlocked, the user will be prompted to open the
    UEM Client
    to start the conditional access enrollment.