Rolling out "require compliant device" without a flood of tickets
Requiring a compliant device is one of the strongest Conditional Access controls you can apply. It's also one of the easiest to get wrong. A step-by-step rollout.
On this page
A Conditional Access policy that requires a compliant device means only devices managed by Intune and meeting your compliance rules can reach corporate data. Stolen passwords and tokens become far less useful. The challenge is rolling it out without blocking people who are doing nothing wrong.
- 01Fix compliance policies
- 02Report-only policy
- 03Plan exceptions
- 04IT, then pilots
- 05Everyone
1. Get compliance right first
- Make sure every platform you allow has a compliance policy assigned.
- Review the tenant setting Mark devices with no compliance policy assigned as. Set it to Not compliant, so a missing policy isn't a free pass.
- Use a sensible grace period for non-urgent settings, so a device isn't blocked the moment something minor changes.
- Check the compliance report and fix the common failures, often OS version, BitLocker or Defender.
2. Run the policy in report-only
Create the Conditional Access policy targeting all users and all cloud apps, with the grant control Require device to be marked as compliant. Leave it in report-only for a week or two and review who would be blocked.
3. Plan the exceptions
- Break-glass accounts: always excluded.
- Guests: their devices are managed by their own organisation. Either exclude them or trust their compliance claims in cross-tenant access settings.
- Personal devices: decide whether they're blocked or allowed limited browser access through a separate policy.
- Device enrolment: new devices need to reach Intune before they're compliant. Check that enrolment and the Company Portal aren't blocked.
Managed devices
- Full access in apps and browser
- Must stay compliant
Personal devices
- Browser only, or app protection policies
- Downloads blocked for sensitive data
Excluded
- Break-glass accounts
- Specific service scenarios, documented and reviewed
4. Enforce in waves
Turn it on for IT first, then pilot departments, then everyone. Brief the service desk with the common fixes: run a compliance check in Company Portal, install pending updates, enable BitLocker.
What users will see
When a device fails, the user gets a message that the device must be managed or compliant, with a link to Company Portal or settings to fix it. On Windows, the most common fixes are installing updates and restarting. The compliance troubleshooting wizard walks the service desk through the rest.
Watching the rollout
- Filter sign-in logs for Conditional Access failures with error 53000 (device not compliant) each morning of the rollout.
- Watch the Intune compliance report for devices stuck in "Not evaluated".
- Keep the previous wave stable for a few days before starting the next.