← cd ~/learn
azureblog.co.uk · cheat sheet
Intune compliance and Conditional Access
How a device's compliance state gets from Intune to a Conditional Access decision, and where it goes wrong.
Fits on one A4 page. Checked 9 Oct 2026.
How it fits together
- The device enrols in Intune and receives its compliance policies.
- The device checks in and reports each setting. Intune works out a state: compliant, not compliant, in grace period, not evaluated or error.
- Intune writes the result to the device's object in Entra ID.
- At sign-in, a Conditional Access policy with Require device to be marked as compliant checks that flag. The browser or app must be able to prove which device it's on.
Common Windows settings
- BitLocker, Secure Boot and code integrity (device health)
- Minimum and maximum OS version
- Firewall, antivirus and Microsoft Defender Antimalware
- Password or PIN requirements
- Defender for Endpoint machine risk score
Actions for non-compliance
- Mark device non-compliant: immediately, or after a grace period in days
- Send email to the user, using a notification template
- Send push notification through Company Portal
- Remotely lock the device (not Windows)
- Add device to retire list for an admin to review
Tenant-wide settings to check
- Mark devices with no compliance policy assigned as: set to Not compliant, so unmanaged gaps don't pass.
- Compliance status validity period: devices that stop checking in become non-compliant after this many days (30 by default).
When a compliant device is blocked
- The sign-in log's Device info tab shows no device ID: the browser isn't passing it. Edge does this when signed in with the work account. Chrome needs the Microsoft Single Sign On extension, and Firefox needs Windows single sign-on turned on.
- The device shows as compliant in Intune but not in Entra: sync from Company Portal and wait a few minutes.
- Error AADSTS53000 means the device isn't compliant, or wasn't identified.
Rollout order
Assign compliance policies → watch the compliance report for a couple of weeks → fix the common failures → turn on the Conditional Access policy in report-only → switch it on for a pilot, then everyone. Full guide: rolling out "require compliant device".