azureblog.co.uk
← cd ~/learn
azureblog.co.uk · cheat sheet

Intune compliance and Conditional Access

How a device's compliance state gets from Intune to a Conditional Access decision, and where it goes wrong.

Fits on one A4 page. Checked 9 Oct 2026.

How it fits together

  1. The device enrols in Intune and receives its compliance policies.
  2. The device checks in and reports each setting. Intune works out a state: compliant, not compliant, in grace period, not evaluated or error.
  3. Intune writes the result to the device's object in Entra ID.
  4. At sign-in, a Conditional Access policy with Require device to be marked as compliant checks that flag. The browser or app must be able to prove which device it's on.

Common Windows settings

  • BitLocker, Secure Boot and code integrity (device health)
  • Minimum and maximum OS version
  • Firewall, antivirus and Microsoft Defender Antimalware
  • Password or PIN requirements
  • Defender for Endpoint machine risk score

Actions for non-compliance

  • Mark device non-compliant: immediately, or after a grace period in days
  • Send email to the user, using a notification template
  • Send push notification through Company Portal
  • Remotely lock the device (not Windows)
  • Add device to retire list for an admin to review

Tenant-wide settings to check

  • Mark devices with no compliance policy assigned as: set to Not compliant, so unmanaged gaps don't pass.
  • Compliance status validity period: devices that stop checking in become non-compliant after this many days (30 by default).

When a compliant device is blocked

  • The sign-in log's Device info tab shows no device ID: the browser isn't passing it. Edge does this when signed in with the work account. Chrome needs the Microsoft Single Sign On extension, and Firefox needs Windows single sign-on turned on.
  • The device shows as compliant in Intune but not in Entra: sync from Company Portal and wait a few minutes.
  • Error AADSTS53000 means the device isn't compliant, or wasn't identified.

Rollout order

Assign compliance policies → watch the compliance report for a couple of weeks → fix the common failures → turn on the Conditional Access policy in report-only → switch it on for a pilot, then everyone. Full guide: rolling out "require compliant device".