Setting Up Intune Compliance Policies Correctly

By · Published

Compliance policies in Microsoft Intune define the minimum requirements a device must meet – such as encryption, a current operating system version or active antivirus protection. Intune evaluates every managed device regularly and marks it as compliant or non-compliant.

That evaluation alone does not block anything. It takes effect in combination with Conditional Access: only compliant devices get access to Exchange Online, SharePoint, Teams and other applications.

Sensible minimum requirements for Windows

  • BitLocker encryption required.
  • Secure Boot enabled.
  • Minimum operating system version aligned with your own update process.
  • Microsoft Defender Antivirus active and up to date; with Defender for Endpoint, additionally a maximum allowed device risk score.
  • Firewall enabled.

The underestimated tenant setting

Intune's compliance policy settings include the option “Mark devices with no compliance policy assigned as”. The default is “Compliant”. This means a device that accidentally has no policy assigned is treated as compliant and gets access.

Once your policies are in place, set this option to “Not compliant” so that gaps in assignment do not silently grant access.

Actions for non-compliance

Each policy defines what happens on non-compliance: immediate marking as non-compliant or a grace period of a few days, plus an email notification to the user. A short grace period gives users the chance to install a pending update, for example, before access is blocked.

Linking with Conditional Access

The Conditional Access policy “Require device to be marked as compliant” is – like every new policy – first enabled in report-only mode. This reveals which devices are currently non-compliant or not managed at all before anyone loses access.

Personal devices (BYOD)

For personal smartphones, full device management is often neither wanted nor necessary. App protection policies (MAM) offer an alternative: corporate data is protected inside apps such as Outlook or Teams, for example with a PIN, preventing copy to personal apps and selective wipe. Conditional Access can require an app protection policy for mobile platforms.

Key takeaway

Compliance policies are only as strong as their link to Conditional Access and the default setting for devices without a policy. With clear minimum requirements, grace periods and a rollout through report-only mode, device security becomes measurable without disrupting operations.

Sources