@Mike Sturm, Thanks for posting in Q&A. Based as i know, for inactive device, it will be marked as non-compliant when the device did not check in with Intune for a long time, the default value is 30 days. This is controlled by the built in compliance policy setting "Compliance status validity period (days)" and it can't be excluded. But you can enlarge the days to 60 days to avoid the issue.
Due to vulnerability, I would like to confirm if this is validated by Microsoft Defender for endpoint. If this is controlled by policy, you can unassign the policy to this user or device group to avoid reporting.
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.