@Jason P, Thanks for posting in Q&A. For your issue, we would like to confirm if we set password compliance policy on the device.
Based on my researching, if we have set this, this is a by design behavior. On Windows devices the compliance -password policy affect’s the local user accounts on the machine. However, due to security reasons windows doesn’t store any password metadata so that we don’t expedite brute force efforts. Also, we aggressively purge passwords once they are no longer necessary shortly after logon. As a result, we don’t have the data available at the time that a password policy arrives to know if it is satisfied. And that’s the reason for password must reset at next logon is that the Intune delivered policy affects local accounts and we as have no means to tell what the current password properties the only method is then the OS has to enforce policy is to mark the local accounts as password has expired.
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.