Secure Boot Compliance

Jack Webb 1 Reputation point
2022-07-18T08:30:29.617+00:00

Hi all,

I have a device that has Secure Boot enabled in the BIOS and windows 10 is reporting it as enabled. However intune is reporting the device to be non-compliant because Secure Boot is not enabled. The aim is to have conditional access policies applied blocking access to O365 services/apps on devices that are not compliant with company policy - this is already configured however the device with this issue has been excluded from the policy.

I'm new to Intune so I'm not really sure where to look to resolve instances like this so any help would be much appreciated.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,720 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,334 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2022-07-19T00:44:00.263+00:00

    @Jack Webb , Research and find this can be caused that the "Require Secure Boot to be enabled on the device" setting is supported on some TPM 1.2 and 2.0 devices. For devices that don't support TPM 2.0 or later, the policy status in Intune shows as Not Compliant. TPM 2.0 requires UEFI firmware. A computer with legacy BIOS and TPM 2.0 won't work as expected. Here is a link with more details for the reference:
    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/secure-boot-enabled-device-shows-not-compliant

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.