Configure Conditional Access for Hybrid Microsoft Entra ID Joined Devices
Question details
The user needs to understand how Conditional Access policies apply to Hybrid Microsoft Entra ID joined devices, considering on-premises and cloud variables.
- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Managing and troubleshooting Conditional Access behavior for devices connected to both on-premises Active Directory and Microsoft Entra ID.
- Observed behavior
- Conditional Access behavior fluctuates and depends heavily on specific device registration statuses, authentication methods, and join scenarios.
Before configuring or troubleshooting Conditional Access, ensure you have Conditional Access Administrator privileges in the Microsoft Entra admin center and that your hybrid devices are successfully syncing via Microsoft Entra Connect.
Review Entra ID Documentation and Test Policies in Report-Only Mode
Because hybrid-joined devices interact with both local AD and Entra ID, you must test policies carefully to ensure they evaluate registration status and authentication methods correctly.
Hybrid-joined devices inherently possess dual states. A Conditional Access policy might block or grant access unexpectedly if the device platform, join type, or current network location is not explicitly accounted for in the policy conditions.
It is highly recommended to consult a Microsoft Entra ID specialist if you are deploying complex zero-trust policies across a large hybrid environment.
Log in to the Microsoft Entra admin center, navigate to 'Identity' > 'Devices' > 'All devices', and confirm that your target devices show a join type of 'Hybrid Azure AD joined'.
When creating or editing a Conditional Access policy, set the 'Enable policy' toggle at the bottom of the screen to 'Report-only'. This evaluates the policy during user sign-ins without actually enforcing the block or grant controls.
Go to 'Identity' > 'Monitoring & health' > 'Sign-in logs'. Select a user sign-in event, click the 'Conditional Access' tab, and review how the report-only policy evaluated the hybrid device.
If the policy behavior remains inconsistent, redirect your specific scenario logs to the specialized Azure and Microsoft Entra ID forums or open a Microsoft support ticket.
Boost Enterprise Productivity with WPS Office
While your IT team manages complex infrastructure like Microsoft Entra ID and Conditional Access, your workforce needs a reliable and cost-effective office suite. WPS Office offers a lightweight, highly compatible alternative to Microsoft Office, ensuring seamless document management across all your securely managed hybrid devices.
- 1. Download the Installer: Get the official WPS Office deployment package from the enterprise portal.
- 2. Deploy to Hybrid Devices: Use your preferred endpoint management tool, such as Microsoft Intune, to distribute WPS Office to your hybrid-joined devices.
- 3. Start Working: Open existing Word, Excel, or PowerPoint files instantly with perfect formatting.

Frequently Asked Questions
Why is my Conditional Access policy not applying to a hybrid-joined device?
This often occurs if the device hasn't fully synced with Microsoft Entra ID yet, or if the policy conditions exclude specific authentication methods, network locations, or device platforms that the device is currently using.
Can I require devices to be hybrid joined for Conditional Access?
Yes, you can configure the 'Grant' controls in your Conditional Access policy and select the 'Require hybrid Microsoft Entra joined device' checkbox to restrict access to specific cloud apps.
How do I check if a local Windows device is recognized as hybrid joined?
Open the Command Prompt on the Windows device and run the 'dsregcmd /status' command. Look for 'AzureAdJoined : YES' and 'DomainJoined : YES' at the top of the output to confirm its hybrid status.




