Skip to main content

March 16, 2026 Archived

Conditional Access using Microsoft Entra ID

You can integrate Workspace ONE UEM with Entra ID (formerly Azure AD) platforms from Microsoft, as a device compliance partner, to use endpoint compliance and management status to assess risk and enforce conditional access policies.

This integration enables you to use Workspace ONE UEM’s ecosystem of tools, including the powerful compliance engine, to determine device compliance with your organization’s security standards based on a wide variety of device and user attributes, and share the resulting status with Microsoft. Entra ID interprets this endpoint status information to help you configure detailed conditional access policies.

Prerequisites

  • Omnissa

    • Workspace ONE UEM (any currently supported version) with administrator account

    • Intelligence

      • Available by default for all SaaS environments. You must opt in to Omnissa Intelligence through your Workspace ONE UEM environment and remain opted in for uninterrupted functionality.
      • If you access Omnissa services through Omnissa Connect, then the UEM Data Source must be authorized, and it must remain so. You can view the status from the Intelligence Console by navigating to Integrations > Data Sources > UEM.
      • On-premises customers must configure Omnissa Intelligence, which might require deployment of an on-premises Omnissa Intelligence Connector.

      For more information, see Omnissa Intelligence Requirements.

  • Microsoft

    • Entra ID with relevant Microsoft licensing to configure Microsoft Conditional Access, and administrator access to log-in, add Mobility and Enterprise applications, and grant consent for Enterprise Applications.
      • Microsoft Entra ID (Commercial) - Uses login.microsoftonline.com for authentication and is supported in all Workspace ONE UEM SaaS Commercial and On-premises environments.
      • Microsoft Entra ID for US Government (GCC High) - Uses login.microsoftonline.us for authentication and is supported in Workspace ONE UEM SaaS FedRAMP environments only.
    • Intune with relevant Microsoft licensing to configure Microsoft Partner Compliance Management, and administrator access to configure Partner Compliance Management.

    Please contact your Microsoft representative for detailed licensing requirements for these Microsoft platforms.

Supported Device Platforms

Only fully-managed, MDM-enrolled devices are supported for Entra ID conditional access. Hub-registered or App-registered (through applications such as Boxer, Content, and so on) are not supported. Additional requirements per device platform are noted below.

  • iOS

    • Account Driven User Enrolled (ADUE) devices are supported with Intelligent Hub 25.05.1 and later.
    • Devices enrolled through Intelligent Hub, Browser Enrollment, or Automated Device Enrollment / Device Enrollment Program are supported with all currently supported versions of Intelligent Hub.
  • Android

  • macOS

  • Windows

    • Windows OOBE-enrolled devices are supported in Workspace ONE UEM Commercial SaaS with Entra ID Commercial only. Entra ID GCCH is not supported.

Supported Deployments

Workspace ONE UEM currently supports the following deployments of Microsoft Entra ID.

  • Microsoft Entra ID (Commercial) - Uses login.microsoftonline.com for authentication.

    • Supported for all commercial SaaS and On-premise environments of Workspace ONE UEM.
  • Microsoft Entra ID for US Government (GCC High) - Uses login.microsoftonline.us for authentication.

    • Supported in Omnissa-hosted Workspace ONE UEM SaaS FedRAMP environments only.

Additionally, you can now integrate a single Entra ID tenant with multiple Workspace ONE UEM environments. Each Workspace ONE UEM Organization Group (OG) where you wish to configure the same Entra ID tenant for conditional access, must belong to a distinct Workspace ONE UEM environment. In other words, you can have one Entra ID tenant for multiple UEM environments, but you cannot have one Entra ID tenant for multiple OGs in a single UEM environment.

On Premises Environments with Console on Closed Network

On premises environments with UEM Console server hosted on an internal/restricted network, including those without outbound access to the relevant Intelligence URLs as noted here, must use a Console URL with an associated SSL Certificate. Console URLs using just http are not supported for conditional access integration.

The conditional access Log capability might not function on such environments, since it requires outbound access from Console to Intelligence.

Configure Conditional Access Using Entra ID

Take the following steps to enable conditional access with Entra ID. These steps assume you are running a browser supported by Workspace ONE UEM and that you can have multiple browser tabs open at the same time.

  1. For iOS, Android, or macOS devices, in one tab of your browser, log in to the Microsoft Intune admin center using your administrator account credentials.

    1. Navigate to Tenant Administration > Connectors and Tokens > Partner Compliance Management > Add Compliance Partner.

    2. In the Create Compliance Partner > Basic tab, configure the following as applicable.

      • Compliance partner - Select Workspace ONE Conditional Access (in Entra ID GCC High, select Workspace ONE Conditional Access GCCH).

      • Platform - Select your desired platform (iOS, Android, and macOS).

    3. In the Create Compliance Partner > Assignments tab, configure user and group inclusions and exclusions as required.

    4. In the Create Compliance Partner > Review + create tab, review your configuration details then select Create.

      If you want to configure conditional access for more than one platform, repeat these steps for each platform.

  2. In a new tab of your browser, log in to the Microsoft Entra ID admin console using your administrator account credentials.

    1. (OPTIONAL) Configure Entra ID conditional access policies based on your organizational needs. For more information, see Microsoft Conditional Access Overview.

    2. For Windows devices, add AirWatch by Omnissa enterprise application to your Entra tenant.

      1. In the Azure Management Portal instance, select your directory and navigate to the Mobility (MDM and WIP) tab.

      2. Select Add Application, select the AirWatch by Omnissa app, and choose Add.

  3. In a new tab of your browser, log into your Omnissa Workspace ONE UEM environment using your administrator account credentials.

    1. Switch to a Customer type organization group (OG). Entra ID conditional access and prerequisite configurations in Workspace ONE UEM are currently supported at customer type OGs only.

    2. Navigate to Monitor > Intelligence and make sure you have opted in. If not, complete the opt-in process. For more information, see Omnissa Intelligence documentation.

    3. Navigate to Groups & Settings > All Settings > System > Directory Services.

    4. In the Server tab, scroll down to the Advanced section.

    5. For Azure AD Integration, select the Enabled slider.

  4. Switch to the Microsoft Entra ID tab of your browser.

    1. Select Microsoft Entra ID from the menu. The Microsoft Entra ID Overview page appears. To find the Microsoft Entra tenant ID or primary domain name, look for Tenant ID and Primary domain in the Basic information section.

    2. Copy this Tenant ID to the clipboard. For more information, see Microsoft Entra ID Tenant ID.

  5. Switch back to the Workspace ONE UEM tab of your browser.

    1. Paste the Tenant ID in the Directory ID text box under the Azure AD Integration slider.

    2. Scroll down and locate the setting Use compliance data in Azure conditional access policies and then select its Enabled slider.

    3. (OPTIONAL for Windows devices) For Use compliance data in Azure conditional access policies for Windows, select the Enabled slider.

    4. (OPTIONAL for iOS, Android, and macOS devices) For Use compliance data in Azure conditional access policies for iOS, Android, and macOS, select the Enabled slider.

      1. When prompted for a redirect to Microsoft, select Proceed, which launches a new tab in your browser. Authenticate with your Entra ID administrator credentials, and Accept the Permissions Request in the resulting consent page. Once consent is granted, the Workspace ONE Conditional Access app is added to your Enterprise applications in Azure.

      2. Upon successful completion, return to UEM and select Complete.

    5. The System Settings screen for Directory Services displays featuring all the sliders you enabled previously.

    6. Select the Save button.

You can use the same Entra ID tenant in more than one UEM environment by repeating the larger steps 3-5 above, while logged in as an administrator in each UEM environment. Entra ID will show only one instance of the Workspace ONE Conditional Access app even when integrated with multiple Workspace ONE UEM environments.

Register Devices for Conditional Access, Microsoft Entra ID

Platforms requiring user interaction for device registration typically support two paths.

Self-service Registration Flow: Your device end users can self-register using a deeplink that you push to their devices. Steps for deploying the deeplink are specified in the platform-specific guides below.

Remediation Flow: Alternately, the device end user can log in or attempt to access data through a native application that is subject to an Entra ID Conditional Access policy which requires the device to be marked as compliant. If the device end user’s access is restricted, then the end user is redirected by Microsoft to register for Conditional Access through Intelligent Hub. Direct the device end user to follow these prompts.

Register iOS Devices for Conditional Access Using Entra ID

Intelligent Hub and Microsoft Authenticator are required applications on iOS devices using Entra ID conditional access. Assign and deploy both applications to your iOS devices as managed applications through the Workspace ONE UEM Console. For more information, see Introduction to Managing iOS Applications.

The Self-service Registration Flow can be activated in two ways.

  • Activate the Conditional Access Registration button on Intelligent Hub.
  • Configure and deliver a deeplink as a Webclip.

Registration Button in Intelligent Hub (Recommended)

Starting with Intelligent Hub for iOS version 25.11, you can simplify the registration process for end users by activating the Conditional Access Registration button within Hub. To activate the Registration button, follow the procedure:

  1. In Workspace ONE UEM console, navigate to Groups & Settings > All Settings > Apps > Settings and Policies > Settings.

  2. Enable Custom Settings, and paste the following Key-Value pair in the Custom Settings field and then select Save.

    { "displayRegisterConditionalAccessButton":true }

You can see the Conditional Access Registration button once the Hub applies these settings. On previously enrolled devices, you may need to force-quit and re-launch the Hub for the changes to take effect.

Registration Webclip

To configure and deliver a deeplink as a Webclip, follow the steps:

  1. In Workspace ONE UEM console, navigate to Resources > Apps > Web Links, choose Add Application, select Apple iOS as the platform, and select Continue.

  2. In the Details tab, provide an appropriate Name for the Web Link - this appears as the name of the Webclip icon on the device and in the Hub Catalog.

  3. Set URL to airwatch://conditionalaccess?partner=microsoft

  4. Optionally, provide a relevant Description.

  5. In the Assignment tab, select the relevant Smart Groups for assignment and configure Exclusions if needed.

  6. Set Push to Auto (Recommended).

  7. Configure Advanced settings, select Save and Publish.

  8. Instruct device end users to initiate registration by clicking on the Webclip deployed.

Managed app config for Microsoft Authenticator

You are not required to deploy managed app config for Authenticator through Workspace ONE UEM. It is recommended that the {sharedDeviceMode} configuration key is not used. If it is used, set the following parameters for dedicated devices.

Value Type: Boolean Configuration Value: False

Register Boxer and iOS Native Mail for Conditional Access Using Entra ID

Microsoft conditional access is available for applications that contain Microsoft Authentication Library (MSAL). This feature can be extended to applications such as Workspace ONE Boxer and the iOS Native Mail client that support SafariViewController through an SSO Extension profile.

  1. In Workspace ONE UEM console, navigate to Resources > Profiles & Baselines > Profiles > Add Profile.

  2. Create an Apple iOS profile with Management Type set to Imperative and Context set to Device with the following recommended configuration in the SSO Extension payload.

    1. Extension Type: Generic.

    2. Extension Identifier: com.microsoft.azureauthenticator.ssoextension

    3. Type: Redirect

    4. URLs:

    • Additional Settings (Custom XML): <dict> <key>TeamIdentifier</key> <string>SGGM6D27TK</string> </dict>
      • SGGM6D27TK is the Team Identifier for iOS applications published by Microsoft to the App Store.
  3. Assign to the relevant Smart Groups, then select Save and Publish.

Register Android Devices for Conditional Access Using Entra ID

Intelligent Hub and Microsoft Authenticator are required applications on an Android device using Entra ID conditional access. Assign and deploy both applications to your Android devices as managed applications through the Workspace ONE UEM Console. Additionally, deploy any other applications subject to conditional access policies as managed applications through Workspace ONE UEM. For more information, see Managing Android Applications using Omnissa Workspace ONE UEM.

The Self-service Registration Flow can be activated in two ways.

  • Activate the Conditional Access Registration button on Intelligent Hub.
  • Configure and deliver a deeplink as a Bookmark.

Registration Button in Intelligent Hub (Recommended)

Starting with Intelligent Hub for Android version 25.11, you can simplify the registration process for end users by activating the Conditional Access Registration button within the Hub.

To activate the registration button, follow the procedure:

  1. In Workspace ONE UEM console, navigate to Groups & Settings > All Settings > Apps > Settings and Policies > Settings.

  2. Enable Custom Settings, and paste the following Key-Value pair in the Custom Settings field and then select Save.

    { "displayRegisterConditionalAccessButton":true }

You can see the Conditional Access Registration button once the Hub applies these settings. On previously enrolled devices, you may need to force-quit and re-launch the Hub for the changes to take effect.

Registration Bookmark

To configure and deliver a deep link as a Bookmark, follow the procedure:

  1. In Workspace ONE UEM console, navigate to Resources > Apps > Web Links, choose Add Application, select Android as the platform and Continue.

  2. In the Details tab, provide an appropriate Name for the Web Link - this appears as the name of the Bookmark icon on the device and in the Hub Catalog.

  3. Set URL to awagent://com.airwatch.androidagent?component=conditionalaccess&partnertype=microsoft

  4. Optionally, provide a relevant Description.

  5. In the Assignment tab, select the relevant Smart Groups for assignment, and configure Exclusions if needed.

  6. Set Push to Auto (Recommended).

  7. Set Add to Homescreen to Yes.

  8. Instruct end users to initiate registration by selecting the Bookmark deployed.

Android Shared Device Mode

Workspace ONE UEM supports Shared Device Mode (SDM) registration for Entra ID Conditional Access on Android devices. For more information, see Shared Device Mode (SDM) for Microsoft Azure Conditional Access Policies on Android Devices.

Register macOS Devices for Conditional Access Using Entra ID

Intelligent Hub is required on any macOS device to use Entra ID conditional access.

To enable the Self-service Registration Flow, take the following steps to configure and deliver a deeplink as a Webclip.

  1. In Workspace ONE UEM console, navigate to Resources > Apps > Web Links, choose Add Application, select Apple macOS as the platform and Continue.
  2. In the Details tab, provide an appropriate Name for the Web Link - this appears as the name of the Bookmark icon on the device and in the Hub Catalog.
  3. Set URL to wsonehub://conditionalaccess?partner=microsoft
  4. Optionally, provide a relevant Description.
  5. In the Assignment tab, select the relevant Smart Groups for assignment, and configure Exclusions if needed.
  6. Set Push to Auto (Recommended).
  7. Instruct end users to initiate registration by selecting the Bookmark deployed.

For Conditional Access registration, macOS Intelligent Hub requires the end user to authenticate with Entra ID. The Entra ID account used for authentication (for example, user@your-entra-id-domain) must match a specific attribute in Workspace ONE UEM, associated with the user record to which the device is enrolled.

  1. If you have configured Hub Service for macOS, then the UEM enrollment user record must include:

    a. UserPrincipalName = user@your-entra-id-domain. If UserPrincipalName is empty

    b. Email Address = user@your-entra-id-domain

  2. If you have not configured Hub Services for macOS, then the enrollment user record in UEM must include:

    a. Email Address = user@your-entra-id-domain

To find the characteristics of the enrollment user in Workspace ONE UEM, navigate to Accounts > Users > Details View (of the specific user).

Register Windows Devices for Conditional Access Using Entra ID

Windows devices enjoy native support for Entra ID conditional access integration and do not require additional configuration for registration. Intelligent Hub relays the Azure Device Identifier and Azure User Identifier to Workspace ONE UEM through samples, once it obtains them from the OS. UEM marks the device as registered for conditional access, and relays management and compliance status updates to Entra ID.

Additional Resources, Features, and Troubleshooting

You have access to other resources for troubleshooting or investigatory purposes.

Device Registration Status

Version: Workspace ONE UEM 2310 and above

  • The Device Details > Summary page displays an Azure Active Directory Registration status in the Security card. This status is set to Enabled when UEM receives a valid Azure Device Identifier (Azure Device ID) from a device - this data is relayed to UEM by Intelligent Hub.
  • The Azure Device ID is displayed in the Device Info card.

Conditional Access Log

The Device Details > More > Conditional Access Log page provides a history of interactions between Workspace ONE and Microsoft for the device, focused on calls between the Compliance Broker and Microsoft Intune/Graph APIs. This history includes the Management and Compliance statuses relayed to Microsoft, and the date/time at which this information was relayed. The Event Details typically contain the following.

  • Request Send Time Stamp
  • Partner Device ID - The Azure Device ID
  • Partner User ID - The Azure User Identifier
  • Message ID
  • Device Management Status - The UEM Enrollment status of the device
  • Compliance Status - The UEM Compliance status of the device
  • API Request Body - The details included in the body of the API request sent to Microsoft
  • API Response Body - The details included in the response received from Microsoft

Device Events and Device Troubleshooting Log

A subset of the information displayed in the Conditional Access Log is also available in the following pages.

  • Device Events: Monitor > Events and Logs > Device Events.

  • Device Details > More > Troubleshooting > Event Log.

    These pages contain two types of events:

    • Conditional Access Device Registration - Recorded when the UEM receives relevant data from the Hub, and relays it to the Compliance Broker (to be forwarded to Microsoft)
    • Conditional Access Device State Change - Recorded when UEM detects a change in the device’s Compliance or Enrollment status, and sends an update to the Compliance Broker (to be forwarded to Microsoft)

    The Event Data for these events typically contains:

    • Device UUID - Workspace ONE UEM’s unique identifier for the device
    • Device Management Status - Enrollment status in UEM
    • Compliance Status - Compliance status in UEM
    • Compliance Broker Request - Details of information relayed to the Workspace ONE compliance broker service, to be relayed to Microsoft
    • Successful - Denotes if the request was successfully sent to the Compliance Broker

System Settings

The Directory Services page (navigate to Groups & Settings > All Settings > System > Enterprise Integration > Directory Services) presents additional capabilities for Entra ID conditional access.

  • Sync Azure Services - You can initiate a one-time sync between Workspace ONE and Microsoft Intune so any changes made to Intune’s Partner Compliance configuration are reconciled to Workspace ONE UEM.
  • Re-sync device data from UEM to Azure Services - You can initiate a one-time update to Microsoft, containing compliance and management status for all devices registered for conditional access in your Workspace ONE UEM tenant. Re-sync can be performed once every 4 hours.

REST API

A REST API endpoint is available to retrieve the conditional access registration information for a given device, identified by its Workspace ONE UEM Device UUID.

GET /devices/{deviceUuid}/conditional-access-device-registration-information

The API response contains the following if a device is registered.

  • partner_device_id - Azure Device ID
  • partner_user_id - Azure User ID (String of 0s for SDM-registered devices)
  • partner_tenant_id - Entra ID Tenant ID

Refer to the REST API documentation available at <YourAPIURL>/api/help for additional details. To see an explanation about how to access API documentation in your specific environment, see Accessing API Documentation.

Omnissa Intelligence

The Azure Device Identifier is also available in Omnissa Intelligence, displayed as Microsoft AAD Device ID, and can be used in Reports and Freestyle Workflows.

Deactivate Conditional Access

If you want to deactivate Conditional Access integration with Entra ID in a proper and comprehensive manner, take the following steps.

  1. Ensure that you are opted into Workspace ONE Intelligence.

  2. In Workspace ONE UEM, navigate to Groups & Settings > All Settings > System > Enterprise Integration > Directory Services.

  3. Disable Use compliance data in Azure Conditional Access policies for iOS, Android, and macOS and Use compliance data in Entra Conditional Access policies for Windows, if they are enabled.

  4. Then disable Use compliance data in Azure Conditional Access policies. Save the changes.

  5. Optionally, remove the Workspace ONE Conditional Access application from your Entra ID tenant, then remove partner compliance configurations from the associated Intune admin console.

Update Entra ID Tenant

If you already enabled conditional access at a given OG and want to replace the Entra ID tenant associated with that OG, take the following steps.

  1. Deactivate the existing integration in Workspace ONE UEM.

    1. Ensure that you are opted into Workspace ONE Intelligence.

    2. In Workspace ONE UEM, navigate to Groups & Settings > All Settings > System > Enterprise Integration > Directory Services.

    3. Disable Use compliance data in Azure Conditional Access policies for iOS, Android, and macOS and Use compliance data in Entra Conditional Access policies for Windows, if they are enabled.

    4. Then disable Use compliance data in Azure Conditional Access policies. Save the changes.

    5. Optionally, remove the Workspace ONE Conditional Access application from your Entra ID tenant, then remove partner compliance configurations from the associated Intune admin console.

  2. Configure integration with the new tenant by completing the Configuration steps across Workspace ONE UEM, Intune, and Entra ID.

Save Failure, Support and Troubleshooting

CategoryDetails
IssueConfiguration - Directory Services page fails to Save when conditional access is Enabled
SymptomsConsole shows “Save Failed Provision tenant failure.”
Relevant LogsWeb Console
ResolutionEnsure Workspace ONE conditional access is selected as the compliance partner for at least one platform in the Intune admin console. See Microsoft Intune.
Additional DetailsWeb Console logs typically show the following.

Could not save Conditional Access configurations at Organization Group: 1234 because of error: provision-tenant-failure and errorDetails: Failed to provision MICROSOFT tenant

Followed by a status code.

401 UNAUTHORIZED

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…