Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (2023)

Posted by Dishan M. Francis | Dec 2, 2018 | Azure | 0 |

Last Updated on December 2, 2018 by Dishan M. Francis

In my previous posts I explained how we can add devices to Intune and how we can push applications to those. This is another blog post under same category and in here I am going to talk about managing device compliances using Microsoft Intune.

In an infrastructure, we know how trusted device should looks like. We use different tools and services to make sure those does. As a simple example, most use group policies to make sure firewall, windows updates are up and running. But now, it is hard to define infrastructure boundaries as many people use same device for work and personal stuff. More and more people are working remotely. So, administrators are losing control over the devices. With Microsoft Intune we can easily define compliance policies and detect devices which is not meeting infrastructure requirements. It is similar how network policy server works in BYOD environment.

In this demo I am going to create compliance policy to detect the devices which doesn’t have firewall and antivirus services running. once it detects, it also should send notification to IT department so they aware that non-compliance device is in network.

1. To start, log in Azure portal as Global administrator

2. Then go to All Services | Intune | Devices

3. Under devices I can see my demo device is in healthy state.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (1)

4. First, we need to create device group, so I can target it with the policy. to do that go to Intune home page and click on Groups

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (2)

5. Then click on New Group

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (3)

6. Then create the new security group with demo device.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (4)

7. As next step, we need to create notification. This is email template that we going to fire when policy detects a non-compliance device. To do that go to Intune home page, Device compliance | Notifications | Create notification

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (5)

8. Then create template with relevant data.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (6)

9. Now we have everything ready for the policy. To start click on Policies | Create Policy

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (7)

10. In next window type policy name & select the platform. In my demo it is going to be for Windows 10 device.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (8)

11. Then click on Setting | System Security & set Require for Firewall, Antivirus, Antispyware & Defender.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (9)

12. Next, click on Actions for noncompliance | Add and select the action option as send email to end user. Under message template select new notification we created.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (10)

13. Above will only send notification to the global admin account that I am using to setup this policy. I also need to send notifications to IT department. To do that, click on Additional recipient and select the IT distribution group.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (11)

14. After all settings are in place, click on Create

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (12)

15. Once policy is in place, click on it and then click on Assignments

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (13)

16. Then select the device group we created in the beginning. This will be the target for the policy.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (14)

17. Now it is time for testing. I went to my demo pc and turn off the firewall.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (15)

18. Then go to Intune | Devices | All Devices and click on the demo device.

19. In new window click on Sync so it will forcefully speed up the policy evaluation.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (16)

20. Then after few minutes, I go to new policy and click on overview. In there I can see 1 device is detected.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (17)

21. If I go in details I can see the device is non-compliant with the new policy and it is flagged because it is not running firewall services.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (18)

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (19)

22. As expected, it sent email notification to IT department as well.

Step-by-Step Guide to Microsoft Intune Device Compliances - Technical Blog | REBELADMIN (20)

As we can see it does the job. It is easy to setup and easy to detect. This marks the end of this blog post. If you have any further questions feel free to contact me on rebeladm@live.com also follow me on twitter @rebeladm to get updates about new blog posts.

FAQs

How do I make my Intune device compliant? ›

Create the policy
  1. Sign in to the Microsoft Intune admin center.
  2. Select Devices > Compliance policies > Policies > Create Policy.
  3. Select a Platform for this policy from the following options: ...
  4. On the Basics tab, specify a Name that helps you identify them later.
Mar 8, 2023

How do I check my Intune device compliance? ›

You can view details about a devices compliance to the validity period setting. Sign in to Microsoft Intune admin center and go to Devices > Monitor > Setting compliance. This setting has a name of Is active in the Setting column.

What is an Intune device compliance policy? ›

Intune Compliance Policy for device help to protect company data; the organization needs to ensure that the devices used to access company apps and data comply with certain rules.

What are the top 3 best practices when implementing Intune? ›

7 Microsoft Intune Best Practices
  • Simplify access management by using Azure AD groups. ...
  • Apply Mobile Application Management (MAM) regulations to apps. ...
  • Leverage the Intune Company Portal mobile app. ...
  • Bring Microsoft Defender ATP into use. ...
  • keep track of performance using reports. ...
  • Set up conditional access.
Apr 13, 2023

How often do devices in Intune evaluate compliance? ›

How often do devices in Intune evaluate compliance?
PlatformFrequency
iOSEvery 15 minutes for 6 hours, and then every 6 hours
Mac OS XEvery 15 minutes for 6 hours, and then every 6 hours
AndroidEvery 3 minutes for 15 minutes, then every 15 minutes for 2 hours, and then every 8 hours
2 more rows
Aug 9, 2018

What is the difference between compliant and non compliant Intune? ›

If your device is compliant, then it is granted access. Non-compliant devices are not granted access. You can also monitor device compliance and troubleshoot compliance-related issues in Intune by going to Devices > Overview > Compliance status.

What happens if a device is not compliant in Intune? ›

The result of this default is when Intune detects a device isn't compliant, Intune immediately marks the device as noncompliant. After a device is marked as noncompliance, Azure Active Directory (AD) Conditional Access can block the device.

How do I check my TPM status in Intune? ›

To identify the category of a device encryption failure, sign in to the Microsoft Intune admin center and select Devices > Monitor > Encryption report. The report will show a list of enrolled devices and show if a device is encrypted or ready to be encrypted, and if it has a TPM chip.

How do I check my device compliance in SCCM? ›

View compliance results in the Configuration Manager console
  1. In the Configuration Manager console, click Monitoring > Deployments.
  2. In the Deployments list, select the configuration baseline deployment for which you want to review compliance information.
Oct 3, 2022

What 2 items do you need to create a custom compliance policy? ›

Before you can add custom settings to a policy, you'll need to prepare a JSON file, and a detection script for use with each supported platform. Both the script and JSON become part of the compliance policy.

Does Intune compliance require BitLocker? ›

Currently, Intune supports only the encryption check with BitLocker. For a more robust encryption setting, consider using Require BitLocker, which leverages Windows Device Health Attestation to validate Bitlocker status at the TPM level.

What is a requirement for all devices using Microsoft Intune? ›

Intune requires Android 8. x or higher for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies. This requirement does not apply to Microsoft Teams Android devices as these devices will continue to be supported.

What is the difference between MDM and MAM in Intune? ›

As you can see from the definitions above, the simple difference between MDM and MAM is that MDM is about control of devices like tablets and smartphones, whereas MAM is about controlling specific corporate applications and their data.

What are the five phases in the Microsoft Intune application lifecycle? ›

By understanding these phases, you'll have the details you need to get started with app management in Intune.
  • Add. The first step in app deployment is to add the apps, which you want to manage and assign, to Intune. ...
  • Deploy. ...
  • Configure. ...
  • Protect. ...
  • Retire. ...
  • Next steps.
Mar 7, 2023

Is Intune a MDM solution? ›

Microsoft Intune is a cloud-based mobile device management (MDM) solution that helps you manage and secure endpoints. It offers many features to simplify access, including: Single sign-on (SSO) to corporate resources - no need to remember multiple passwords.

How do I fix non compliant devices in Intune? ›

Please try the following action:
  1. Please create a new compliance policy and the settings in the policy are same as the old one.
  2. Create a new group and add just a user in the group.
  3. Add the new user group in the new compliance policy's assignments.
  4. Please use the user to login in the device which shows "Not compliant".
Dec 12, 2021

How do I fix non compliant Intune? ›

Add actions for noncompliance
  1. Sign in to the Microsoft Intune admin center.
  2. Select Devices > Compliance policies > Policies, select one of your policies, and then select Properties. ...
  3. Select Actions for noncompliance > Add.
  4. Select your Action:
Feb 21, 2023

How do I make my device compliant in Azure? ›

Sign in to the Azure portal as a Conditional Access Administrator, Security Administrator, or Global Administrator. Browse to Azure Active Directory > Security > Conditional Access. Select New policy. Give your policy a name.

What 2 items do you need to Create a custom compliance policy? ›

Introducing custom compliance settings

Those settings relies on a JSON file and a PowerShell script that must be uploaded to Microsoft Intune. That PowerShell script is used to detect a specific configuration and that JSON file is used to define the actual rule.

Top Articles
Latest Posts
Article information

Author: Allyn Kozey

Last Updated: 19/11/2023

Views: 6264

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Allyn Kozey

Birthday: 1993-12-21

Address: Suite 454 40343 Larson Union, Port Melia, TX 16164

Phone: +2456904400762

Job: Investor Administrator

Hobby: Sketching, Puzzles, Pet, Mountaineering, Skydiving, Dowsing, Sports

Introduction: My name is Allyn Kozey, I am a outstanding, colorful, adventurous, encouraging, zealous, tender, helpful person who loves writing and wants to share my knowledge and understanding with you.