Intune rules for a given platform that set the standard a device has to meet, like a minimum OS version or encryption, along with what happens if it falls short. Conditional Access can then deny access to devices that don't comply.
Also called compliance policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Device compliance policy in context, with comparison tables and the common traps.
Terms in this definition
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
Related terms
- Actions for noncompliance
What a compliance policy does, in order, when a device fails it. Marking the device noncompliant always happens, at day 0 unless you add a grace period; you can also send an email or push notification, lock the device remotely or put it on the retire list.
- Compliance policy settings
Settings that apply to compliance across the whole Intune tenant. One decides how devices without a compliance policy are treated (Compliant unless changed, and Not compliant is advised alongside Conditional Access); the other is how long a compliance status stays valid, 1 to 120 days with 30 as default.
- Mark device noncompliant
An action in a compliance policy. It marks the device noncompliant at once, or after a set grace period; until that period ends the device's state reads InGracePeriod.
- Mark devices with no compliance policy assigned as
Applies across the whole tenant and defaults to Compliant. It decides what Conditional Access makes of a device that has no compliance policy; choose Not compliant so that access depends on a genuine policy check.