Our Story

Who we are and how we solve complex IT challenges.

Our Certifications

Microsoft certifications and partnerships validating our technical expertise.

Leadership

Meet the Experienced Leadership Team Driving WME’s Success

Advisory Updates

Expert guidance on Microsoft, security, and compliance developments.

Case Studies

Real-world outcomes from complex Microsoft-focused IT engagements.

Podcast

Podcasts, panels, and interviews where WME leaders share how they help high-growth companies and IT partners scale.

Ebooks

Practical guides on the Microsoft moves you can’t afford to get wrong.

Financial Industry

Secure technology solutions for regulated banks and financial institutions.

Healthcare

Secure Microsoft solutions for compliant, connected, and modern healthcare organizations.

Manufacturing

Cloud and security solutions supporting modern manufacturing operations.

Non-Profit

Cost-efficient Microsoft solutions for mission-driven organizations.

Public Sector

Microsoft-based IT services for secure public sector modernization.

High Tech

Scalable cloud, security, and staffing for fast-growing technology companies.

SMBs

Scalable cloud, security, and staffing for fast-growing technology companies.

Cloud Migration Services

Transition your workloads to the cloud securely for greater scalability and performance.

Data Migration Services

Securely transfer your business data with minimal downtime and maximum integrity.

Application Migration Services

Move your applications seamlessly to modern platforms with minimal business disruption.

Identity & Security Migration Services

Strengthen identity management and security while transitioning to modern Microsoft solutions.

Security Solutions

Protect your business with proactive cybersecurity, compliance, and risk management solutions.

Endpoint Management

Secure, manage, and monitor every device with modern endpoint management solutions.

Licensing Optimization

Get discounted pricing, a dedicated licensing team, and a plan that fits how many seats you actually use.

Power Platform

Unlock the full potential of the Microsoft Power Platform Suite to streamline operations, automate repetitive tasks, and gain real-time insights that drive business growth.

Sharepoint Solutions

Supercharge your business productivity and enhance visibility through our proven SharePoint expertise.

IT Staffing

Connect with skilled IT professionals to strengthen your team and accelerate project delivery.

Accounting & Finance

Connect with experienced accounting and finance professionals to support your business goals.

Microsoft Intune Policies – Windows Compliance

March 8, 2016

Microsoft Intune Policies – Windows Compliance

In this next post focusing on Intune, we will talk about Compliance polices. These policies are fairly basic, and mainly focus on device security. I will present a best practices setup, but you should always define these in accordance with your company’s policy. Pay attention to the support OS when looking at these policies. Some things, especially for Windows x86 and x64, cannot be configured here.

To create a compliance policy, go to the Policies section of the Intune management webpage and click on “Compliance Policies”. Click New to create a new policy. You can give your policy a name and description.

System Security

All of the options for System Security revolve around passwords and encryption. The applicable operating systems will be shown once you enable the policy.

The first two settings should be left as the default. The only one you might consider changing is the minimum password length by making it more than four. Remember though that your users will have to type this in every time they unlock the device, and they likely will not have a keyboard. I prefer to have six, because I also allow the passwords to never expire (more on this in a minute). The simple password option here prevents users from using a password like 1234 or 1111. You cannot define the definition of simple password.

Next is some advanced password settings. Again, these are my preference. I prefer not to have the password expire, and to only require numeric passwords. This is why I set my minimum length to six characters. I allow them to never expire because we’re talking about physical access to the device. I can lock and wipe the device if needed, so I’m not concerned about password expiration. I do require six characters so that it’s more difficult to brute-force the device.

Next is encryption. You’ll notice that this is supported on everything but iOS, because iOS devices are encrypted by default. If you open the information tab, it says something to this affect. Basically, you just need a password to encrypt an iOS device. Also note that this setting will only apply if the device itself supports encryption.

Device Health

Finally, we have a setting that will not allow Intune to function on a jailbroken or rooted device, for obvious security reasons.

After you have configured your compliance policy, you can deploy it to your devices.

Compliance Policy Settings

There’s a button at the top of the Compliance Policies view that we need to talk about:

When you click the “Compliance policy settings” button, you get this:

This configures a global policy that says if a device does report a status in x days, the device is treated as noncompliant. The default is 30 days, which is probably a good number considering an Intune-managed device can communicate with only an Internet connection. You should configure this as it fits with your company.

Share:

Facebook
Twitter
LinkedIn

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.

Related Posts