Default policy query

TechUST 416 Reputation points
2024-04-25T06:47:40.15+00:00

Hi ,

I've seen some non-compliant machines in my Intune environment due to default compliance policies. My query is about where these default policies are applied from and how to remediate them, as I haven't seen any such policies in configuration or compliance.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,729 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,365 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 43,381 Reputation points Microsoft Vendor
    2024-04-25T07:14:55.3733333+00:00

    @TechUST, Thanks for posting in Q&A. In Fact, the default compliance policies in Intune are tenant-wide settings that are like a built-in compliance policy that every device receives. These policies set a baseline for how compliance policy works in your Intune environment, including whether devices that haven’t received any device compliance policies are compliant or noncompliant and Compliance status validity period (days).

    User's image

    https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started#compliance-policy-settings

    For the non-compliant device, please check which setting shows non-compliant. For example, if "Is active" shows not compliant, then it means the device hasn't reported to Intune for a long time which is longer than the days we configure under "Compliance status validity period (days). ".

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. xenia 391 Reputation points
    2024-04-25T07:15:31.2266667+00:00

    @TechUST There are two parts to compliance policies in Intune:

    • Compliance policy settings – Tenant-wide settings that are like a built-in compliance policy that every device receives. Compliance policy settings set a baseline for how compliance policy works in your Intune environment, including whether devices that haven’t received any device compliance policies are compliant or noncompliant.
    • Device compliance policy – Platform-specific rules you configure and deploy to groups of users or devices. These rules define requirements for devices, like minimum operating systems or the use of disk encryption. Devices must meet these rules to be considered compliant.

    So, how did you configure under Endpoint security > Device compliance > Compliance policy settings? If you configure the setting "Mark devices with no compliance policy assigned as" to "Not compliant", it means devices that haven’t received a device compliance policy are considered noncompliant.

    https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started

    0 comments No comments