This article describes how to enable additional security measures for Hybrid AAD Join.
- Hybrid AAD Join
-
Enable Conditional Access
-
This is performed via the Azure administrative console and will deny access to any device that is not Hybrid Azure AD joined.
-
Please refer to the Require Hybrid Azure AD joined devices section in the following guide: How To: Require managed devices for cloud app access with Conditional Access.
-
-
Leverage Device Trust
-
If Windows Device Trust has not yet been configured, refer to the following guide: Enforce Okta Device Trust for managed Windows computers.
-
In the Office 365 application, create a sign-on policy that allows access to devices using Legacy Authentication.
-
In the Okta Admin Console, click Applications.
-
Find and click the desired Office 365 application.
-
Click the Sign On tab.
-
In the Sign On Policy section, edit an existing rule or click Add Rule to create a new one.
-
In the Client > If the user's client is any of these section, ensure that Exchange ActiveSync/Legacy Auth is checked.
-
In the Device Trust section, ensure that Trusted is checked.
-
Click Save.
-
-
