We have implemented conditional access policies and have set up named locations for our office locations. Users accessing company resources from these locations are not prompted for multi-factor authentication (MFA). This works great,

However, we have received feedback from several users when they are working at home instead of reciving the MFA thing once daily (which is how we have it set) they need to login to each app i.e word, outlook, teams, one drive , power bi… and sometimes you only have to login to outlook and then they all work long and shor there is no ryme or reason but its a pain in the a$$.

Additionally, we would like to know if it is possible to designate a device as “trusted,” such as a company-issued laptop, which would not require MFA, while personal devices would still require MFA for accessing company resources.

Anyone know if this is possible? It is working as its suppose to however when end users have to MFA its asking way to many times in way to many apps.

8 Spice ups

Sure, you can use Filter for devices to target specific devices, as detailed here: Filter for devices as a condition in Conditional Access policy - Microsoft Entra ID | Microsoft Learn

Make sure to also cover the last section in the article, as there are some caveats detailed therein.

1 Spice up

You can use company-devices which are Hybrid-Joined or AzureAD-Joined:

What is a hybrid Azure AD joined device? - Microsoft Entra | Microsoft Learn

What is an Azure AD joined device? - Microsoft Entra | Microsoft Learn

What are Azure AD registered devices? - Microsoft Entra | Microsoft Learn

In theory you can also trust AzureAD Registerd devices. But normal User can register devices to AzureAD. So this may be a security risk.

Because of the Logon-Problems: Have you selected any options of your CDA-Policy in the Section Access controls → Session?