Azure AD authentication for Windows hybrid joined device vs unmanaged device. Managed device performs Cert authentication + PRT Authentication (transparent) + MFA - returns device "ismanaged" attribute. Unmanaged device performs Username+Password+MFA - does not return "ismanaged" attribute. This can then be used in ZPA Policy for posture control