RCA / INTUNE / ENTRA ID / COMPLIANCE

Device compliant?
Prove the signal.

A structured RCA for users blocked because Entra Conditional Access requires a compliant device while Intune reports a different compliance state.

Access is blocked

Capture the exact application, user, device, timestamp and sign-in result before changing the Conditional Access policy.

Correlate the device

Confirm the device used for the sign-in matches the Entra device record and the endpoint being evaluated by Intune.

Find the failed signal

Identify which compliance requirement is failing and whether the endpoint has received the latest policy and check-in state.

INVESTIGATION FLOW

Trace the trust chain.

01Sign-in
02Device
03Intune
04Compliance
05Entra CA
06Access
07Verify

Device identity

Verify the device record, ownership/join state and that the sign-in came from the expected endpoint.

Compliance state

Review the effective compliance policy and determine the specific requirement producing non-compliance.

Policy decision

Correlate the Entra sign-in with the Conditional Access policy requiring compliant-device access.

Root-cause rule

Do not bypass Conditional Access simply because the user is blocked. First prove the device identity, Intune compliance state, policy freshness and Conditional Access decision. Remediate the failed compliance signal, allow policy/check-in propagation, then reproduce the original sign-in to verify.