M365 Defender Medium risk does not honor Compliance rule in Intune

Pavel yannara Mirochnitchenko 13,336 Reputation points MVP
2021-10-12T18:30:02.94+00:00

I have device onboarderd to M365 Defender and the risk level is now Medium. My Compliance policy requires low risk level to be compliant. Still, device is compliant and can access O365 apps which I deny for non-compliant devices. This situation I tracked down had lasted this entire day.

139991-image.png

139953-image.png

139879-image.png

Microsoft Security | Intune | Other
{count} votes

4 answers

Sort by: Most helpful
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2021-10-13T01:53:08.627+00:00

    @Pavel yannara Mirochnitchenko , From your description, it seems the the machine risk score is not synchronized to the Intune for this device from security center. We can wait for some time to see if it can synced.

    However, If the issue still persists after we monitoring 1 day, please collect the following information to clarify:

    1. Could you let us know how many devices are affected? What are the enrollment method?
    2. Is there any device working well? What is the difference between the working devices and not working devices?
    3. Try to click sync on the device to get the latest policies to see if the result will be different.

    If there's any update, feel free to let us know.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Rahul Jindal [MVP] 10,911 Reputation points MVP
    2021-10-12T22:03:23.313+00:00

    The status against security recommendations in Defender can take 24 hrs to update.

    0 comments No comments

  3. Pavel yannara Mirochnitchenko 13,336 Reputation points MVP
    2021-10-13T18:12:06.643+00:00

    I start to see this as a massive problem on multiple machines, which has been in use for entire day. Defender classifies them as Medium risk, compliant policy requires Low and they still are compliant. I could open support case via M365 portal to solve this out...


  4. Rahul Jindal [MVP] 10,911 Reputation points MVP
    2021-10-13T21:31:27.127+00:00

    Have you checked why the devices are showing medium risk? Are the alerts\incidents recent?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.