Whether Device compliant Info can be passed by a corporated managed MDM enrolled android device with Managed Edge (InPrivate)?

Choi, Jacky Chun Wing 20 Reputation points
2026-10-07T08:33:20.55+00:00

I had configured a Conditional Access Policies that detects the device information and determine the SFA / MFA requirement for accessing the corporate application.

CA Policy Overview: 

If device is compliant and device ownership is "Company"--> allow access with SFA 

If device ownership is not "Company"--> allow access with MFA

With the above design, the detection of device ownership and compliance would be a key to affect the user login behaviour. I would like to know if the browser type (inPrivate or not, and Desktop / mobile version) will make a difference to the CA policy evaluation, i.e. whether the CA policy can get the device info (e.g. device id, device ownership, device compliance) with the below conditions: 

Assume some general conditions - 

Device OS: Android Enterprise MDM Enable?: Yes, in corporate owned mode

Case 1: Edge Browser (InPrivate mode) - "View desktop site"

Case 2: Edge Browser (InPrivate mode) - Mobile version

Case 3: Edge Browser (Normal mode) - "View desktop site"

Case 4: Edge Browser (Normal mode) - Mobile version

Thank you for your attention and appreciate any response to my question. Thank you.

BR, Jacky

 

Microsoft Security | Microsoft Entra | Microsoft Entra ID

2 answers

Sort by: Most helpful
  1. Rauh, Alexander 240 Reputation points
    2026-10-08T19:51:30.8466667+00:00

    Hello Choi, Jacky Chun Wing

    as Anton already says Private mode doesn´t pass the device, so case 1 and 2 land in your MFA path (read here). in case 3 and 4 Edge on Android can pass device identity.

    "View desktop site" changes the user agent Conditional access reads the device plafrom from it (read here).So test case 3 once and check the sign in logs and you will see the Device Info shows the detected OS and Compliance and the Conditional access tab shows which policy applied.

    Do your Policies use a device plaform condition or a device filter on deviceOwnership?

    if you have no more question please Accept the Answer so others can also find it faster.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-10-07T08:33:40.0333333+00:00

    Yes, Conditional Access can evaluate device compliance for an Android Enterprise corporate-owned device, but there are important limits for browser scenarios.

    For Android Enterprise devices enrolled in Intune, device-based Conditional Access is supported through Intune and Microsoft Entra ID so that only managed and compliant devices can access protected resources.

    For Microsoft Edge on iOS and Android, Conditional Access can be used so users access Microsoft 365 content only through Edge, and this configuration also prevents users from using InPrivate to access Microsoft 365 endpoints.

    Key points for the scenario:

    1. Compliant device evaluation is supported for managed Android devices Intune compliance policies can mark Android Enterprise devices compliant or noncompliant, and Conditional Access can use that compliance state.
    2. Dedicated device exception If the Android Enterprise device is a dedicated device enrolled without Microsoft Entra shared device mode, users can't sign in to resources protected by Conditional Access policies even if the device is compliant in Intune.
    3. Browser behavior matters For device compliance checks in browsers on iOS, Android, macOS, and some non-Microsoft browsers, Microsoft Entra ID identifies the device by using a client certificate provisioned when the device is registered. The user must select that certificate before continuing.
    4. Edge InPrivate When Edge for iOS and Android is enforced through app-based Conditional Access, the documented behavior is that users are prevented from using InPrivate to access Microsoft 365 endpoints. In that configuration, InPrivate should not be a path that bypasses Conditional Access.

    So for an Android Enterprise corporate-owned, Intune-enrolled device using Edge, Conditional Access can use device compliance information to evaluate access. If the access path is governed by the documented Edge mobile Conditional Access configuration, InPrivate access to Microsoft 365 endpoints is prevented rather than treated as a separate compliant browser session.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.