azureblog.co.uk
← cd ~/posts

Rolling out "require compliant device" without a flood of tickets

Requiring a compliant device is one of the strongest Conditional Access controls you can apply. It's also one of the easiest to get wrong. A step-by-step rollout.

2 min read✓ checked 20 May 2026Intune · Conditional Access · Entra ID
On this page
  1. 1. Get compliance right first
  2. 2. Run the policy in report-only
  3. 3. Plan the exceptions
  4. 4. Enforce in waves
  5. What users will see
  6. Watching the rollout

A policy that requires a compliant device means only devices managed by Intune and meeting your compliance rules can reach corporate data. Stolen passwords and tokens become far less useful. The challenge is rolling it out without blocking people who are doing nothing wrong.

DeviceIntuneEntra IDMicrosoft 365Checks in; reportssettings1Evaluates compliance policyWrites isCompliant todevice object3User opens Outlook4Sign-in evaluated5Policy: require compliantdevice; device is compliantAccess granted7
How compliance reaches a Conditional Access decision.
  1. 01Fix compliance policies
  2. 02Report-only policy
  3. 03Plan exceptions
  4. 04IT, then pilots
  5. 05Everyone

1. Get compliance right first

  • Make sure every platform you allow has a assigned.
  • Review the tenant setting Mark devices with no compliance policy assigned as. Set it to Not compliant, so a missing policy isn't a free pass.
  • Use a sensible grace period for non-urgent settings, so a device isn't blocked the moment something minor changes.
  • Check the compliance report and fix the common failures, often OS version, BitLocker or Defender.

2. Run the policy in report-only

Create the Conditional Access policy targeting all users and all cloud apps, with the grant control Require device to be marked as compliant. Leave it in for a week or two and review who would be blocked.

3. Plan the exceptions

  • Break-glass accounts: always excluded.
  • Guests: their devices are managed by their own organisation. Either exclude them or trust their compliance claims in cross-tenant access settings.
  • Personal devices: decide whether they're blocked or allowed limited browser access through a separate policy.
  • Device enrolment: new devices need to reach Intune before they're compliant. Check that enrolment and the Company Portal aren't blocked.

Managed devices

  • Full access in apps and browser
  • Must stay compliant

Personal devices

  • Browser only, or app protection policies
  • Downloads blocked for sensitive data

Excluded

  • Break-glass accounts
  • Specific service scenarios, documented and reviewed
Deciding what each group gets.

4. Enforce in waves

Turn it on for IT first, then pilot departments, then everyone. Brief the service desk with the common fixes: run a compliance check in Company Portal, install pending updates, enable BitLocker.

Platform tip: on iOS and Android, users access apps through the browser or apps that support device state. Microsoft Edge is the safest choice on mobile for web apps behind this policy.

What users will see

When a device fails, the user gets a message that the device must be managed or compliant, with a link to Company Portal or settings to fix it. On Windows, the most common fixes are installing updates and restarting. The compliance troubleshooting wizard walks the service desk through the rest.

Watching the rollout

  • Filter sign-in logs for Conditional Access failures with error 53000 (device not compliant) each morning of the rollout.
  • Watch the Intune compliance report for devices stuck in "Not evaluated".
  • Keep the previous wave stable for a few days before starting the next.
Next in Conditional Access from zero · part 6 of 7Require phishing-resistant MFA on every PIM activation →Next in Intune for Windows, start to finish · part 6 of 6Intune in September: deployment rings, faster compliance and stricter automation →