Hi Karthik Palani,
Thank you for posting your query on Microsoft Q&A. I am Saiteja from Q&A will be assisting you with your query.
Based on your queries, here is the required information:
Microsoft Entra Private Access mostly works with IP addresses, VPN and applications. We have two types of access, Quick access and per app access.
When your device is not onboarded with Intune, you can configure Quick access with IP addresses and FQDN's.
- IP address:
- Internet Protocol version 4 (IPv4) address, such as 192.168.2.1, that identifies a device on the network.
- Provide the ports that you want to include.
- Fully qualified domain name (including wildcard FQDNs):
- Domain name that specifies the exact location of a computer or a host in the Domain Name System (DNS).
- Provide the ports to include.
- Wildcard FQDNs must be specified in the format
*.contoso.com
You can find more details of Quick Access configuration using this document.
Microsoft Entra private access identifies the device using the above details itself, it will not detect the certificate on your device.
The sign in risks of the user, can be configured from conditional access policy. This conditional access policy can block or request for MFA for user based on the risk type. You can follow the document specified here.
Checking the anti-malware version application before onboarding the device is not available. But we do have Application discovery to manage and view which user is accessing which application and based on which you can configure access accordingly.
Microsoft Entra Private Access secures the cloud entities, resources and private application. If on-premises SharePoint has an object configured in Cloud, it can be secured using Quick access and per app access as well. If your server is configured in Azure as a VM there will be chance to secure it using Microsoft Entra Private access.
Here is the Microsoft document, which talks about Entra private access and key features: https://learn.microsoft.com/en-us/entra/global-secure-access/overview-what-is-global-secure-access
I hope this information is helpful. Please feel free to reach out if you have any further questions.
If the answer is helpful, please click "Accept Answer" and kindly "upvote it". If you have extra questions about this answer, please click "Comment"