Category Filter
 
 

Last updated: August 14, 2026

Conditional Access Policies

This page explains Conditional Access Policies in MDM and how they automate verification and enforcement of corporate resource access across diverse devices. It covers five supported policy types: Microsoft Entra Conditional Access for Office 365 compliance, Okta Device Trust for BYOD and COPE environments, Conditional Exchange Access for Microsoft Exchange Server, Zoho Workspace integration, and Office 365 MAM Policies for app-level security on iOS and Android devices. Use this page to identify and configure the right access control method for your organization.

Access Management is a critical challenge for organizations, especially by those embracing BYOD. Employees often access corporate resources from different locations using multiple devices, making manual validation of authorized users and devices a significant burden for IT administrators.

MDM streamlines this process through Conditional Access policies, automating verification and enforcement. These policies ensure that only compliant and authorized users/devices meeting predefined conditions can access corporate resources, while blocking unauthorized attempts. To achieve this, MDM supports the following policies:

Access Policies:

  • Microsoft Entra Conditional Access: By integrating MDM with Microsoft Entra ID (Office 365), organizations can establish compliance-based access controls for Microsoft 365 applications on mobile devices. This integration ensures secure access while maintaining adherence to organizational policies. 
    Key configuration options include:
  • Okta Device Trust for Managed Devices: Okta Device Trust enables contextual access management by verifying users and devices. When integrated with MDM, it supports diverse ownership models such as BYOD (Bring Your Own Device) and COPE (Corporate-Owned Personally Enabled). Steps include configuring Okta Device Trust for managed devices with MDM to ensure secure and compliant access.
  • Conditional Access for Microsoft Exchange Server: Conditional Exchange Access (CEA) or Exchange Conditional Access policies enable organizations to control and monitor devices accessing their Exchange servers. These policies allow access only to authorized devices, making MDM the central control point. This is especially beneficial in BYOD environments, as it ensures corporate data is accessed securely. Notable features include support for Exchange Server 2019 and overriding server-specific access settings. Administrators can follow detailed steps to configure conditional access for Microsoft Exchange servers.
  • Zoho Workspace Integration: Zoho Workspace supports Conditional Access policies to safeguard organizational resources. By integrating MDM, administrators can enforce device compliance requirements and secure access across diverse endpoints.
  • Office 365 MAM Policies This policy lets you apply security configurations to Office 365 apps installed on iOS and Android devices. Configure data protection, access requirements and conditional launch settings for these apps to secure corporate data being accessed from personally-owned devices.

Frequently Asked Questions

1. What's the difference between Microsoft Entra Conditional Access and Office 365 MAM policies?

Entra Conditional Access controls whether a device can access Office 365 based on device compliance or certificate-based authentication, while Office 365 MAM policies apply app-level security configurations (like data protection and access requirements) to the Office 365 apps themselves, even on personally-owned devices.

2. Do I need to choose only one Conditional Access method?

No. MDM supports multiple Conditional Access policies simultaneously, so you can combine Microsoft Entra Conditional Access, Okta Device Trust, Conditional Exchange Access, Zoho Workspace integration, and Office 365 MAM policies based on your organization's requirements.

3. Which Conditional Access policy should I use for a BYOD environment?

Okta Device Trust and Office 365 MAM policies are well suited for BYOD environments, as they support ownership models like BYOD and COPE and let you secure corporate app data without requiring full device enrollment.

Jump To