You can create a Conditional Access policy to require computers or devices to be marked as compliant in order to access your organization's resources.
For instructions on creating a Conditional Access policy, see the following documentation from Microsoft: Microsoft Entra Conditional Access documentation
You must exclude the "User registration app for Device Compliance" when creating the conditional access policy. Failing to exclude the "User registration App for Device Compliance" will prevent users from being able to register with Entra ID.
There are two authentication types required. The first authentication is performed by Company Portal and will appear as an authentication against Microsoft Intune Company Portal. The second authentication is performed by Jamf Conditional Access.app. When either Microsoft SSO or Platform SSO are enabled, the Jamf Conditional Access.app authentication against the "User registration app for Device Compliance" is brokered through the SSO extension and Entra ID may see this as an authentication against the Microsoft Authentication Broker.