Microsoft Conditional Access

What is MSCA?

Microsoft Conditional Access is Microsoft’s Zero Trust policy engine. We will shortly call it MSCA in the following docs. If your Relution users are synced via Entra ID, you can additionally enable conditional access. If a device managed by Relution changes its state to compliant or non-compliant, we will populate this information to Microsoft. Depending on your Conditional Access policies, it is for example possible to block users from using certain apps if their device is marked as non-compliant.

Supported Platforms

  • Android Enterprise
  • iOS
  • macOS
  • Windows
    • Entra ID joined or enrolled via Autopilot

Preconditions

  • Microsoft Entra ID P1 licenses. See more here.
  • Entra ID configured with users sync active, see Linking Entra ID and Relution
  • Broker app for the authentification.
    • Android Enterprise & iOS - Microsoft Authenticator - is installed when MSCA is activated
    • macOS - Company Portal App - has to be installed on the device. Can be downloaded here.

Limitations

  • Conditional Access as of now can’t be configured within the global orga.
  • Conditional Access can only be activated for all devices of a tenant, filtered by platform