We do conditional access at the Azure level, and a device that doesn't meet some compliance policies on their machine (Windows, macOS, Linux) is unable to access their corporate account until they remediate that.