Can I make Intune managed devices stop being reported in compliance and vulnerability?

Mike Sturm 0 Reputation points
2023-04-21T19:51:53.4433333+00:00

I have devices that have been returned by users that I need to hold for 60 days, but I don't want to be told they need current patches every week or see them show up in vulnerability reports. Is there a way to exempt these devices?

Community Center | Not monitored
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 54,206 Reputation points Microsoft External Staff
    2023-04-24T02:35:53.1266667+00:00

    @Mike Sturm, Thanks for posting in Q&A. Based as i know, for inactive device, it will be marked as non-compliant when the device did not check in with Intune for a long time, the default value is 30 days. This is controlled by the built in compliance policy setting "Compliance status validity period (days)" and it can't be excluded. But you can enlarge the days to 60 days to avoid the issue.

    https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started#compliance-policy-settings

    Due to vulnerability, I would like to confirm if this is validated by Microsoft Defender for endpoint. If this is controlled by policy, you can unassign the policy to this user or device group to avoid reporting.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.