Intune Compliance Policy Preview?

user_zero 1 Reputation point
2024-05-20T16:02:58.8933333+00:00

Presuming I've onboarded a device to Intune, but haven't bound it to a compliance policy yet, is there a way to preview the device's compliance applicable settings through the Intune portal?

Here's the scenario: We're going onboarding devices, some are BYOD, some are not and some are used by high-ranking personnel, within our org.

I onboarded a test device with a handful of compliance settings set. I see that Intune remediated many of the non-compliant settings on the test machine - this is both a boon and a curse. It's good that the settings were remediated, but I'd hate for that to happen on a user's machine (especially an executive's machine!) without them expecting it.

I was hoping to find a way to onboard a device to intune, and review the devices' compliance related settings (ie: simple passwords or whether the firewall was enabled) before adding the device to a compliance policy, so that I can get a feel for which users we'll have to schedule and guide through the changes they may notice. In my initial test, i didn't enable any of the compliance settings, and nothing gets reported under the device > device compliance. I added a few more settings and can now see which were originally compliant, which were remediated, and which need user intervention to make compliant.

It would be helpful to see (using my above example), whether a device is allowing simple passwords or doesn't have it's firewall enabled, before adding it to compliance policy that would change those settings.

Thanks in advance!

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
142 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 9,790 Reputation points Microsoft Vendor
    2024-05-21T01:51:59.7833333+00:00

    @user_zero, Thanks for posting in Q&A.

    Based on my experience, currently, there is no such way in Intune to check a device's compliance-related settings before adding it to a compliance policy. If you want to know whether a device is compliant with certain compliance policies, you have to either check at the device end or go through a policy analysis after assigning the device a compliance policy in order to come up with the device's setting status. After that you can correct the non-compliant settings on device.

    You can refer to the following links to set up compliance policies and monitor the status of the device after applying the policies

    https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started

    https://learn.microsoft.com/en-us/mem/intune/protect/compliance-policy-monitor

    As for device enrollment, here are some methods mentioned in the following link.

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment#choose-your-platform-enrollment-guide

    Hope above information can be helpful.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.