Outage Status Now

Guides / Conditional Access: device not compliant or not joining

Last reviewed 5 Oct 2026

Conditional Access: device not compliant or not joining

Blocked by Conditional Access with "device not compliant"? What users can try, what Intune compliance means, and how admins read the sign-in log.

The user types their password, passes MFA, and then Microsoft stops them with a block about the device. The wording varies: You can't get there from here, Device is not compliant, Device is not hybrid joined, or Use a device that is managed by your organisation. That is Conditional Access doing its job. It is almost never "Microsoft is down".

Is it Entra or Conditional Access?

A real Entra ID outage stops sign-in for many tenants at once and shows on the Entra ID status page and in Service health. One person blocked after a successful password and MFA is policy. Open the message carefully: if it names compliance, hybrid join, approved client apps, or a named Conditional Access policy, you already know the category.

What the user can try

  1. Use the work PC. If the block is on a personal laptop or phone and the company laptop works, stop troubleshooting the personal device. The policy wants a managed endpoint.
  2. Company Portal. On Windows and mobile, open Company Portal and check device status. If it says not compliant, open the details — missing PIN, overdue OS update, BitLocker off, or a required app not installed are the usual reasons.
  3. Sign out everywhere and back in. On the blocked device, clear the work account from Windows Settings → Accounts → Access work or school (or remove the account from the mobile Authenticator / Outlook app) and add it again so the device re-registers.
  4. Update the OS and reboot. Compliance policies that require a minimum OS build fail quietly until the device reports again. Install updates, reboot, wait ten minutes, then retry.
  5. Another browser is not a bypass. If the policy requires a compliant device or an approved app, Chrome versus Edge will not help. That is the point of the policy.

Admin checks (Entra and Intune)

Break-glass and guests

Emergency access accounts should be excluded from most Conditional Access policies by design. Guests and partners often fail device compliance because their devices are not in your Intune. Use a separate guest policy: MFA and terms of use, not full compliance, unless the contract says otherwise.

When to escalate

Escalate to Microsoft when the sign-in log shows the device as compliant and hybrid joined, the policy should have granted access, and the block still fires for several users on known-good devices. Attach the correlation ID from the error page and the sign-in log entry. For a single overdue laptop, it is a desk or Intune fix — not a severity-one outage call.

Related status pages

Related guides

FAQ

What does device not compliant mean in Conditional Access?
Intune (or another MDM) has evaluated the device against your compliance policy and marked it Noncompliant — for example missing BitLocker, an old OS build, or no PIN. Conditional Access then blocks apps that require a compliant device.
Can I bypass Conditional Access with another browser?
No. If the policy requires a compliant or hybrid-joined device, changing from Edge to Chrome does not help. You need a device that meets the grant control, or an admin change to the policy.
How do admins see which policy blocked the user?
In the Entra admin centre, open the user sign-in log, then the Conditional Access tab. It lists each policy and whether it succeeded or failed, including device state.
Is a Conditional Access block the same as Entra being down?
No. A block after password and MFA means Entra answered and applied policy. A real Entra outage stops sign-in broadly and appears on the official status page.

Still broken? Check another tool