Expanding Device Posture Checks with Intune
Cloudflare has expanded its integration with Microsoft Endpoint Manager (Intune), giving joint customers additional device telemetry for Zero Trust access decisions. The integration pulls Compliance State and other device posture data from the Microsoft Graph API in real time, so policies are evaluated against up-to-date device health signals on every connection request.
The existing Intune integration already let customers check whether a device management profile such as Intune is present before granting access. Now, organizations can layer Intune's compliance data into policies for both applications and outbound web traffic. This allows security teams to identify, investigate, and remediate threats more quickly, using conditional access that adapts as device conditions change.
Microsoft's Graph API delivers continuous posture assessments across all endpoints in an organization, regardless of location, network, or user. With this integration, those additional data points can be factored into Cloudflare Access and Gateway policies, so a device must meet a defined compliance state before a user proceeds.
Using the Integration in Zero Trust Policies
The integration works across Cloudflare's entire Zero Trust platform. Administrators can incorporate Compliance State checks into existing Access and Gateway policies, then combine those conditions with other Zero Trust capabilities such as Browser Isolation, tenant control, or antivirus checks through tenant control.
Setting it up requires adding Microsoft Intune as a device posture provider in the Cloudflare Zero Trust dashboard under Settings → Devices → Device Posture Providers. The necessary credentials — Client ID, Client Secret, and Customer ID — come from the Microsoft Endpoint Manager admin center.

Once the posture provider is configured, administrators can define device posture checks requiring specific criteria aligned with Intune's data, such as device Compliance State.

Those machine-level rules can then be referenced by conditional Access and Gateway policies, enabling or denying access to applications, networks, or sites. Admins can block or isolate users or user groups whose devices are flagged as malicious or out of compliance.

In the months ahead, Cloudflare plans to broaden the Microsoft Graph API integration further, allowing customers to correlate additional fields from the Graph API in their security policies.

Existing Cloudflare Zero Trust customers interested in using the Intune integration can find setup guidance in the documentation. For questions, Microsoft joint customers can also use the contact form or reach out to their Cloudflare account team.



