What are Intune Compliance Policies?
Updated: Dec 1, 2024
Compliance policies allow you to create a set of rules that determine whether an enrolled device is compliant or not. If a device is not compliant, you can choose a resulting action that will happen.
A device's compliance status can be seen from the device list in Intune (you may need to add the column first) See below:
Compliance Settings
Before you start creating compliance policies for devices in your organization, note that there are "default" compliance settings that apply to all devices. These compliance settings are NOT to be confused with compliance policies.
The compliance settings are configurable. To access them, see the steps below:
Open Endpoint Manager (Intune)
Select Devices > Compliance
Select the Compliance Settings tab
There are two configurable items within compliance settings; don't forget that these settings apply to your entire tenant (all of the devices):
Mark devices with no compliance policy assigned as: this option allows you to mark devices that have not received any compliance policy as either "compliant" or "noncompliant." (if you plan on creating configuration policies for all operating systems, then you may want to configure this setting to mark devices without a compliance setting as noncompliant so you can track which devices haven't received a policy)
Compliance status validity period (days): specify the number of days a device can go without "checking in" (verifying its received policies) with Intune before it is marked as noncompliant (note that devices that are offline for long periods will start to show as noncompliant if this value is set to a low number)
Compliance Policies
Compliance policies are created per operating system and can be scoped (assigned) to all users/devices or specified groups.
To create a new compliance policy, see the steps below:
Open Endpoint Manager (Intune)
Select Devices > an OS (ex. Windows) > Compliance Policies
Select + Create Policy
Once you've verified the correct platform, name the new policy and select Create
Now you can configure the compliance policy settings, the actions for noncompliance, and then the assignment for the policy (who/what will be assigned the policy)