Office365 - Conditional Access Policy - Can Okta support device registration? (win 7/win 10) Skip to main content
https://support.okta.com/help/answers?id=9062a000000qunoqak&refurl=http%3a%2f%2fsupport.okta.com%2fhelp%2fanswers
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
1
2
3
4
5
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Ask Search:
Alan JohnstoneAlan Johnstone 

Office365 - Conditional Access Policy - Can Okta support device registration? (win 7/win 10)

For device registration to work, Microsoft documents that ADFS or your 3rd party idp must be configured in a certain way.  I don't have ADFS as I have Okta instead, but really need the benefit of conditional access.  (more than just a pass/fail on logon - I can fine tune what you get access to based on device trust/home devices)

Has anyone been able to set this up in Okta?  Can Okta support this scenario?  I don't want to have to spin up ADFS.

https://docs.microsoft.com/en-us/azure/active-directory/device-management-hybrid-azuread-joined-devices-setup

Want to limit access to certain features of o365 based on whether the device is domain joined / compliant. (but still allow them to sign in and access certain things regardless)
Mihai NegoitaMihai Negoita (Okta, Inc.)
Hi Alan,

The following features might be what you are looking for:

https://help.okta.com/en/prod/Content/Topics/Mobile/Okta_Mobile_Device_Trust_Windows%20desktop.htm
https://support.okta.com/help/Documentation/Knowledge_Article/Getting-Started-with-Office-365-Client-Access-Policies

You might have to contact Okta Support to have them enabled for your org.
Alan JohnstoneAlan Johnstone
Hi Mihal:  Device trust only does pass/fail.  I'm looking at limiting access within o365 based on this information, not blocking it entirely.  This is supported by o365 based on an azure ad hybrid joined computer, but Microsoft documenation says ADFS is required, or your IDP must support it.  Can you help?
Rico JardineroRico Jardinero
Was an answer ever given here? I am running now into the wall where I need to setup "Issuance of Claims"
 
Alan JohnstoneAlan Johnstone
Okta does not support this at this time.  Only ADFS can do this.  I'm told Okta is looking at doing this in the future.  Call Okta support and add your name to the list of customers wanting this!  I need it sooner than later too.