
Explanation:

Box 1: No
User1 is member of Group1 and has Device1.
Device1 is not Microsoft Entra ID joined.
Note: Requiring a hybrid Microsoft Entra ID joined device is dependent on your devices already being hybrid Microsoft Entra ID joined.
Box 2: Yes
User2 is member of Group1 and has devices Device2 and Device3.
Device2 is Microsoft Entra ID joined.
Device2 is excluded from CAPolicy1 (which would block access to Site1).
Box 3: Yes
User2 is member of Group1 and has devices Device2 and Device3.
Device3 is Android and is Microsoft Entra ID registered.
Device3 is excluded from CAPolicy1 (which would block access to Site1).
Note: On Windows 7, iOS, Android, macOS, and some third-party web browsers, Microsoft Entra ID identifies the device using a client certificate that is provisioned when the device is registered with Microsoft Entra ID. When a user first signs in through the browser the user is prompted to select the certificate. The end user must select this certificate before they can continue to use the browser.
Reference:
https://learn.microsoft.com/en-us/azure/active-directory/devices/howto-hybrid-azure-ad-join
https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy- compliant-device