Our Story

Who we are and how we solve complex IT challenges.

Our Certifications

Microsoft certifications and partnerships validating our technical expertise.

Leadership

Meet the Experienced Leadership Team Driving WME’s Success

Advisory Updates

Expert guidance on Microsoft, security, and compliance developments.

Case Studies

Real-world outcomes from complex Microsoft-focused IT engagements.

Financial Industry

Secure technology solutions for regulated banks and financial institutions.

Healthcare

Secure Microsoft solutions for compliant, connected, and modern healthcare organizations.

Manufacturing

Cloud and security solutions supporting modern manufacturing operations.

Non-Profit

Cost-efficient Microsoft solutions for mission-driven organizations.

Public Sector

Microsoft-based IT services for secure public sector modernization.

High Tech

Scalable cloud, security, and staffing for fast-growing technology companies.

SMBs

Scalable cloud, security, and staffing for fast-growing technology companies.

Cloud Migration Services

Transition your workloads to the cloud securely for greater scalability and performance.

Data Migration Services

Securely transfer your business data with minimal downtime and maximum integrity.

Application Migration Services

Move your applications seamlessly to modern platforms with minimal business disruption.

Identity & Security Migration Services

Strengthen identity management and security while transitioning to modern Microsoft solutions.

IT Staffing

Connect with skilled IT professionals to strengthen your team and accelerate project delivery.

Accounting & Finance

Connect with experienced accounting and finance professionals to support your business goals.

Licensing Support

Discover the benefits of both CSP and On-premises licensing options and find the best fit for your unique business needs. From cost savings to flexibility, we’ve got you covered.

Power Platform

Unlock the full potential of the Microsoft Power Platform Suite to streamline operations, automate repetitive tasks, and gain real-time insights that drive business growth.

Sharepoint Solutions

Supercharge your business productivity and enhance visibility through our proven SharePoint expertise.

Security Solutions

Protect your business with proactive cybersecurity, compliance, and risk management solutions.

Endpoint Management

Secure, manage, and monitor every device with modern endpoint management solutions.

Microsoft Endpoint Manager – Intune Compliance Policies

October 2, 2022

Hi everyone! Many organizations want to be sure corporate devices to meet requirements to protect access to corporate network or company data only for compliant devices. By using the Intune Compliance Policies, you can create and assign access on corporate devices or personal devices, then you can alert your users, or you can block access to corporate resources with Azure AD Conditional Access.

There are two parts of Intune compliance policies:

  • Policies which define criteria and rules we can configure and deploy on devices;
  • Settings which define actions for noncompliant devices and determine how compliance policies will interact with user devices.

You can configure compliance policies from Devices – Compliance policies or from Endpoint security – Device compliance. First, let’s configure compliance settings:

Here you can configure tenant-wide options:

  • Mark devices with no compliance policy assigned as will mark all of the devices as noncompliant until compliance policies assigned;
  • Enhanced jailbreak detection applies to iOS devices only;
  • Compliance status validity period (days) specifies a period in which device must sent a compliance status report. If device can’t send a report to Intune for some reasons device will be marked as noncompliant. By default, period is 30 days. In my lab environment I reconfigured it to 1.

In Notifications you can create a message template will be sent to users if device is threated as noncompliant. Click Create notification, provide a name for a template:

Then click Next and provide a notification message:

Then click Next and Create.

Go to Policies to create a first compliance policy. Click Create, then choose a planform – Windows 10 and later and click Create. Provide a name of the policy and click Next. On Compliance settings page you can configure Custom Compliance:

First, you need to upload PowerShell script in Scripts and prepare JSON file. JSON file identifies custom compliance settings you want to check and PowerShell script will discover settings you defined in JSON file.

Device Health:

Windows Health Attestation Service with a series of checks can validate boot state.

Device Properties:

In this section I configure a minimum OS version, device with OS build below will be marked as noncompliant.

Configuration Manager Compliance:

I don’t use integration with Microsoft Endpoint Configuration Manager, we will check compliance status from Intune only.

System Security consists of a couple of sub-sections, first is Password:

I don’t require password in my example. Next is Encryption:

I don’t configure this setting as well.

Device Security:

I want to check if firewall, antispyware and antivirus (built-in antivirus or any 3rd party antivirus that can be registered with Windows Security Center) are enabled.

Defender:

In this section we configure Microsoft Defender antimalware and real-time protection checking as part of our compliance policy.

Windows Defender for Endpoint:

I keep default settings.

When you configured all the settings you want to check click Next. On the Actions for noncompliance tab, you configure sequence of actions for noncompliant devices. At least one action must be configured:

In my example, I want to inform user twice his device is noncompliant (remember, we have a message template?). If user doesn’t run remediation steps we mark this device as noncompliant and after 30 days devices will be marked as retired. Then this device can be manually removed from Retire noncompliant devices section.

Click Next. On Assignments tab I add two dynamic Azure AD groups with personal and unknown devices:

And then click Create.

Right after the enrollment Windows 10 devices checks policies and settings every 3 minutes for 15 minutes, then every 15 minutes for 2 hours, and then around every 8 hours. Already enrolled device checks Intune settings every 8 hours. Also, end user can trigger policy check from Company Portal or from Access work or school:

In this example we don’t block access to corporate date (it will be covered in next blog), we just check a compliance status. To do that go to Devices – Compliance status:

On this dashboard you can find high-level overview of compliance status and policies.

To get more detailed information go to Devices – Monitor – Compliance:

Setting compliance report shows an information about all of the compliance settings:

Click on a setting to see additional details:

Click on device name, then on Device compliance:

By default, Built-In Device Compliance Policy is assigned on all of the devices. This policy contains three settings:

Click on setting you created to see a compliance status:

You can also check compliance status from Devices – Compliance policies – <click on policy name>:

Happy deployment!

You can also learn more about Microsoft EndPoint Patch Management Strategies by clicking here:

Share:

Facebook
Twitter
LinkedIn

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.

More Posts

Copilot Cowork: Credit-Based Billing

Until now, Copilot Cowork has been included with M365 Copilot Premium licenses. Now that Cowork has moved out of public preview, Cowork is introducing a ...
Read Full Article
SharePoint OTP Retirement Is Coming in July 2026

SharePoint OTP Retirement Is Coming in July 2026 — What IT Admins Need to Do Before Access Breaks

Starting July 2026, external users who access OneDrive and SharePoint files through legacy SPO OTP links will start receiving access denied — silently, with no ...
Read Full Article
Power Virtual Agents Is Gone. Here's What Replaced It and Why It Matters.

Power Virtual Agents Is Gone. Here’s What Replaced It and Why It Matters.

If someone on your team still calls it “Power Virtual Agents,” they’re working from an outdated map. Microsoft retired the product on November 15, 2023 ...
Read Full Article

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.
Subscription Form email