@Bradley, Thanks for posting in Q&A. For conditional access policy, it is a feature in Microsoft Entra ID which is used to control app access with cloud resource.
From your description, it seems the sign in is blocked by conditional access policy and seems with compliance policy. Based as I know, there's a setting "Require device to be marked as compliant (Intune)" which is related with compliance. Please go to Microsoft Entra ID to see if we have set such policy. For this setting, the device you use to login needs to be enrolled into Intune and its compliance status in Intune needs to be compliant.
For detailed information, you can look into sign in log
https://learn.microsoft.com/en-us/entra/identity/conditional-access/troubleshoot-conditional-access
As a workaround, your method is OK. You can send the attachment without needing any login to make it read.
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.