Skip to main content
This guide applies to macOS, iOS, and iPadOS devices

About Microsoft Device Compliance

Iru Endpoint’s Microsoft Device Compliance (MSDC) integration combines Iru Endpoint’s device management and compliance features with Microsoft’s conditional access capabilities, ensuring only managed and compliant devices can access corporate resources.

How It Works

Iru Endpoint’s Microsoft Device Compliance (MSDC) integration combines Iru Endpoint’s device management and compliance features with Microsoft’s conditional access capabilities. Built through Microsoft’s device compliance partner program, this integration simplifies the setup and configuration process between Iru Endpoint and Microsoft and streamlines the deployment of required applications through the Iru Endpoint Library. Once configured and devices are registered with Microsoft, Iru Endpoint’s device inventory and compliance data can be used in Microsoft Conditional Access policies. This ensures that only managed and compliant devices can access corporate resources. Iru Endpoint’s MSDC integration supports macOS, iOS, and iPadOS devices.

Prerequisites

All Devices

  • Devices must be managed by Iru Endpoint
  • A Microsoft user directory integration must be set up in your Iru Endpoint tenant
  • A user from the configured directory integration must be assigned to the device record
  • Device users must be assigned a Enterprise Mobility + Security license, which includes Microsoft Entra ID Premium and Microsoft Intune
  • A Microsoft user account that can accept requested app permissions
  • Iru Endpoint must be configured as a device compliance partner in Intune

Configuration Overview

Below are the basic steps required to set up and deploy Microsoft Device Compliance with Iru Endpoint.
1

Configure Iru Endpoint as Device Compliance Partner

3

Deploy Applications

Deploy Applications for end user device registration.
4

Deploy Single Sign-on Profiles

Deploy Single Sign-on Profiles.
The Microsoft Single Sign-on Extension only needs to be deployed if it is not already deployed in your environment for the device platforms you have configured.