A cloud-based identity and access management service for securing user authentication and resource access
Yes, Conditional Access can evaluate device compliance for an Android Enterprise corporate-owned device, but there are important limits for browser scenarios.
For Android Enterprise devices enrolled in Intune, device-based Conditional Access is supported through Intune and Microsoft Entra ID so that only managed and compliant devices can access protected resources.
For Microsoft Edge on iOS and Android, Conditional Access can be used so users access Microsoft 365 content only through Edge, and this configuration also prevents users from using InPrivate to access Microsoft 365 endpoints.
Key points for the scenario:
- Compliant device evaluation is supported for managed Android devices Intune compliance policies can mark Android Enterprise devices compliant or noncompliant, and Conditional Access can use that compliance state.
- Dedicated device exception If the Android Enterprise device is a dedicated device enrolled without Microsoft Entra shared device mode, users can't sign in to resources protected by Conditional Access policies even if the device is compliant in Intune.
- Browser behavior matters For device compliance checks in browsers on iOS, Android, macOS, and some non-Microsoft browsers, Microsoft Entra ID identifies the device by using a client certificate provisioned when the device is registered. The user must select that certificate before continuing.
- Edge InPrivate When Edge for iOS and Android is enforced through app-based Conditional Access, the documented behavior is that users are prevented from using InPrivate to access Microsoft 365 endpoints. In that configuration, InPrivate should not be a path that bypasses Conditional Access.
So for an Android Enterprise corporate-owned, Intune-enrolled device using Edge, Conditional Access can use device compliance information to evaluate access. If the access path is governed by the documented Edge mobile Conditional Access configuration, InPrivate access to Microsoft 365 endpoints is prevented rather than treated as a separate compliant browser session.