Guides / Conditional Access: device not compliant or not joining
Last reviewed 5 Oct 2026
Conditional Access: device not compliant or not joining
Blocked by Conditional Access with "device not compliant"? What users can try, what Intune compliance means, and how admins read the sign-in log.
The user types their password, passes MFA, and then Microsoft stops them with a block about the device. The wording varies: You can't get there from here, Device is not compliant, Device is not hybrid joined, or Use a device that is managed by your organisation. That is Conditional Access doing its job. It is almost never "Microsoft is down".
Is it Entra or Conditional Access?
A real Entra ID outage stops sign-in for many tenants at once and shows on the Entra ID status page and in Service health. One person blocked after a successful password and MFA is policy. Open the message carefully: if it names compliance, hybrid join, approved client apps, or a named Conditional Access policy, you already know the category.
What the user can try
- Use the work PC. If the block is on a personal laptop or phone and the company laptop works, stop troubleshooting the personal device. The policy wants a managed endpoint.
- Company Portal. On Windows and mobile, open Company Portal and check device status. If it says not compliant, open the details — missing PIN, overdue OS update, BitLocker off, or a required app not installed are the usual reasons.
- Sign out everywhere and back in. On the blocked device, clear the work account from Windows Settings → Accounts → Access work or school (or remove the account from the mobile Authenticator / Outlook app) and add it again so the device re-registers.
- Update the OS and reboot. Compliance policies that require a minimum OS build fail quietly until the device reports again. Install updates, reboot, wait ten minutes, then retry.
- Another browser is not a bypass. If the policy requires a compliant device or an approved app, Chrome versus Edge will not help. That is the point of the policy.
Admin checks (Entra and Intune)
- Sign-in logs. In the Microsoft Entra admin centre, open the user's sign-in, then Conditional Access. You will see which policy failed and whether the device was marked compliant, hybrid joined, or not registered.
- Device record. Entra → Devices → All devices. Confirm the device exists, is enabled, and shows as Compliant or Hybrid Azure AD joined as your policy expects. A stale record after a motherboard swap or reimage is common.
- Intune compliance. In the Intune admin centre, open the device → Device compliance. Expand each setting that is Noncompliant. Fix the setting or temporarily exclude the user only if your change process allows it — do not turn the whole policy off for one ticket.
- Network location. Policies that require a trusted named location will block home and hotel IP ranges. Check whether the user is on VPN; some tenants treat the VPN egress as trusted and others do not.
- Grant controls. "Require device to be marked as compliant" and "Require Microsoft Entra hybrid joined device" are different. A cloud-only Entra joined laptop fails a hybrid-join requirement even when it is fully managed.
Break-glass and guests
Emergency access accounts should be excluded from most Conditional Access policies by design. Guests and partners often fail device compliance because their devices are not in your Intune. Use a separate guest policy: MFA and terms of use, not full compliance, unless the contract says otherwise.
When to escalate
Escalate to Microsoft when the sign-in log shows the device as compliant and hybrid joined, the policy should have granted access, and the block still fires for several users on known-good devices. Attach the correlation ID from the error page and the sign-in log entry. For a single overdue laptop, it is a desk or Intune fix — not a severity-one outage call.
Related status pages
Related guides
- Microsoft 365 sign-in loop or 'More information required'
- Intune Company Portal: apps won't install or device pending
- Entra ID / Azure AD password reset email or code not arriving
FAQ
- What does device not compliant mean in Conditional Access?
- Intune (or another MDM) has evaluated the device against your compliance policy and marked it Noncompliant — for example missing BitLocker, an old OS build, or no PIN. Conditional Access then blocks apps that require a compliant device.
- Can I bypass Conditional Access with another browser?
- No. If the policy requires a compliant or hybrid-joined device, changing from Edge to Chrome does not help. You need a device that meets the grant control, or an admin change to the policy.
- How do admins see which policy blocked the user?
- In the Entra admin centre, open the user sign-in log, then the Conditional Access tab. It lists each policy and whether it succeeded or failed, including device state.
- Is a Conditional Access block the same as Entra being down?
- No. A block after password and MFA means Entra answered and applied policy. A real Entra outage stops sign-in broadly and appears on the official status page.