Unable to lock none complaince Device

lalajee 1,821 Reputation points
2022-11-12T22:33:08.803+00:00

hi,

I have enroll Android Device Fully manage into intune using (https://learn.microsoft.com/en-us/mem/intune/enrollment/android-dedicated-devices-fully-managed-enroll#enroll-by-using-a-token)

Then Create dynamic group with following query "(device.deviceOSType -eq "AndroidEnterprise") and (device.deviceOwnership -eq "Company")"

I can see the device in this group

Then I created an Device compliance policy
259825-image.png
259816-image.png

Then I created Conditional Access

  • User: All User
  • Cloud apps or actions: All cloud Apps
  • Conditions: Device platforms -> Include: Android
  • Grant: Grant access: Require device to be marked as compliant

I can still access all of the cloud service even my device is showing as none compliant under intune

When I click on device it show as complaint
259833-image.png

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,501 Reputation points
    2022-11-14T04:20:57.597+00:00

    @lalajee Thanks for posting in our Q&A. From your description, did you mean that the device shows not compliant, but when you click on this target device > Device compliance, this policy shows compliant status? If there is any misunderstanding, please correct me.

    To clarify this issue, we appreciate your help to collect some information:

    1. Please make sure that the setting "Mark devices with no compliance policy assigned as" is set to "compliant".
      259964-image.png
    2. Is this compliance policy named "Android_Enterprise_fully_managed-Compliance" successfully deployed to the target device? What I can see in the screen shot is only the built-in device compliance policy.
    3. Please make sure that you set "Enable policy" to "On" in this conditional access policy.
      259972-image.png
    4. Please try to use a target user sign in a cloud app and check if the conditional access policy is successfully deployed. Please click on Users > Sign-in logs > click on the target user > check if the result under conditional access shows "Success" in intune portal

    If there is anything update, feel free to let us know.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. lalajee 1,821 Reputation points
    2022-11-15T09:08:44.513+00:00

    I took 40 minutes to force the policy but its working now


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.