maciejrebisz.com

IT

How to limit Microsoft Search in Bing to only Intune compliant devices – Mobile-First Cloud-First

maximios March 23, 2023

Microsoft Search in Bing is a power full tool that you can enable as part of your Microsoft 365 subscription. What are you getting as a end user when using Bing to search?? Not only are your users searching the internet but also internal resources:

  • SharePoint Online
  • OneDrive for Business
  • Outlook on the web
  • Office apps on Windows

So wen you as a company is using Microsoft to store and share your documents, then your end users also get search result from your internal data.
So if your are searching for a person or a word then your internal data will show up in the top of bing.com.

Bing search will only show you results that you have the right to as a end user, maybe you don’t want your end users to search in internal resources when they are not on a trusted and compliant device. In that case Azure Active Directory Conditional Access is the right tool for the job. With Conditional Access you can require different controls to look after when a users is accessing corporate data. One of them is compliant device that looks after if your device is meeting the compliance policy from Intune. Again compliance policies can look after different settings and controls that meets with your corporate security policy. I will not cover how to make a device compliant in this blog post.

First you need to check if Microsoft Search in Bing is enabled in your tenant:

Login to Microsoft 365 admin center

  1. Click Settings
  2. Click Services & add-ins
  3. Select on for “Enable Microsoft Search in Bing”

Now you end user can leverage Microsoft Search in Bing when they are logging into bing.
If the end user is on a Azure Active Directory or a Hybrid Joined devices there is single sign-on to Bing search.

How to use Conditional Access with Microsoft Search:

Login to Azure Active Directory admin center

  1. Click Conditional Access
  2. Click New policy

  1. Enter a name for your CA policy : CA – Microsoft Search require compliant device
  2. Click – Assignments – Users and groups
  3. Select -All users or target what meet your security requirements
  4. Select – Exclude if you have some users where this is not applying to.

  1. Click – Cloud apps or actions
  2. Click – Select apps
  3. Click – Select
  4. Applications – search for Microsoft search
  5. Select – Microsoft Search in Bing

  1. Click – Conditions
  2. Click – Device Platforms
  3. Click – Configure Yes

Note : remember to exclude device platforms if your don’t want it to apply to mobile devices as an example

Access Controls:

  1. Select – Grant
  2. Click – Grant Access
  3. Select – Require device to be marked as compliant (Intune enrolled and complaint devices)
  4. Select – Require Hybrid Azure AD joined devices (Applies only to Windows devices that are Domain joined and hybrid joined – not on AAD joined devices)
  5. Select – Require one of the selected controls

Now you are ready to Enable the policy

Note :  Remember always test Conditional Access rules in your test environment or with a test group before deploying in production

How it is end user experience:

When you are using a browser that does have the capability to pass the information about device compliance state to Azure Active Directory the end user will get this message:

If you are on a device that are not compliant you will get a message – Oops – You can’t get this yet

In this case the device is registered to the corporate Azure Active Directory – but not Intune managed so the device cannot be compliant

Read more:

Overview of Microsoft Search

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ How to upgrade Windows 10 1607 with SCCM 1606 (Inplace Task Sequence) – Mobile-First Cloud-First › How to setup local security policy with Intune on Windows 10 1709 with Graph API – Mobile-First Cloud-First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes