Device compliant?
Prove the signal.
A structured RCA for users blocked because Entra Conditional Access requires a compliant device while Intune reports a different compliance state.
Access is blocked
Capture the exact application, user, device, timestamp and sign-in result before changing the Conditional Access policy.
Correlate the device
Confirm the device used for the sign-in matches the Entra device record and the endpoint being evaluated by Intune.
Find the failed signal
Identify which compliance requirement is failing and whether the endpoint has received the latest policy and check-in state.
Trace the trust chain.
Device identity
Verify the device record, ownership/join state and that the sign-in came from the expected endpoint.
Compliance state
Review the effective compliance policy and determine the specific requirement producing non-compliance.
Policy decision
Correlate the Entra sign-in with the Conditional Access policy requiring compliant-device access.
Do not bypass Conditional Access simply because the user is blocked. First prove the device identity, Intune compliance state, policy freshness and Conditional Access decision. Remediate the failed compliance signal, allow policy/check-in propagation, then reproduce the original sign-in to verify.