Traffic to https://www.adatum.com:8433: In WCFPolicy1, the only rule specifies *.adatum.com as the allowed domain but without specifying a particular port. Typically, web content filtering applies only to standard HTTP/HTTPS traffic (ports 80 and 443). Since this traffic is over port 8433, which is nonstandard, it would not match the allow rule in WCFPolicy1. Thus, it will be blocked from all devices. Traffic to https://www.fabrikam.com: Since there is no rule in WCFPolicy1 to specifically allow or block traffic to fabrikam.com, the Conditional Access policy CAPolicy1 will govern access. CAPolicy1 is configured to grant access only if a user's device is compliant. Therefore, traffic to https://www.fabrikam.com will be allowed only from compliant devices