Step 9 β Create a CA policy that blocks noncompliant devices
Click π Conditional Access in the sidebar, then + New policy.
β’ Step 1 (Name): Type any name, e.g. Require compliant device.
β’ Step 2 (Assignments): Leave defaults (All users, All cloud apps). Click Next.
β’ Step 3 (Conditions): No changes needed. Click Next.
β’ Step 4 (Grant): Select Require device to be marked as compliant. Click Next.
β’ Step 5 (Enable): Set to On to enforce immediately, or Report-only to test first. Click Create.
π‘ Setting the policy to On is required to complete Step 14 (CA Enforced). You can always set it to Report-only first, then re-create with On selected.