Hey folks! We currently use Microsoft Entra ID for SSO across our cloud apps, which works great, but we have a glaring security gap. Right now, as long as an employee has valid credentials (and MFA), they can log in. The problem is, they can do this from devices that are totally unpatched, have BitLocker disabled, or even have blocklisted apps installed. We need a way to completely block access to our corporate data if the device’s security posture is compromised. Has anyone successfully set up a workflow where the actual health of the device dictates whether they get access to cloud apps?