How to integrate non compliant devices to intune?

Paul Parakal 0 Reputation points
2026-06-05T08:49:54.1666667+00:00

HI,

My company has Microsoft 365 e5 license, in a summary report received yesterday 90% of the devices are complaint, while 10% of the devices are non-compliant. We cross checked on the CAP and other such policies and found no issue.

Now I want to know if there is any other specific license for devices (like conf tv/iot hardware/kiosk devices)

Microsoft Security | Intune | Compliance

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-05T08:50:23.25+00:00

    Intune device compliance is controlled by policies and tenant-wide compliance settings, not by separate per-device licenses beyond what is already included in Microsoft 365 E5.

    Key points for the scenario:

    1. Licensing
    • Microsoft 365 E5 already includes the necessary rights to use Intune and device compliance policies for supported platforms.
    • There is no separate Intune “device license” required specifically for non-compliant devices, conference room systems, kiosks, or IoT-type hardware in the context of compliance reporting.
    • Compliance is evaluated per device based on assigned policies and tenant compliance settings, not by an additional license type in the documentation provided.
    1. Why devices show as non-compliant
    • Devices are marked compliant or noncompliant based on:
      • Platform-specific compliance policies assigned to users/devices.
      • Tenant-wide Compliance policy settings.
    • If a device has no compliance policy assigned, its status depends on the tenant setting Mark devices with no compliance policy assigned as:
      • Compliant (default) – devices without a compliance policy are treated as compliant.
      • Not compliant – devices without a compliance policy are treated as noncompliant.
    • When using Conditional Access with device compliance, the recommendation is to set Mark devices with no compliance policy assigned as to Not compliant so only confirmed-compliant devices can access resources.
    1. How to bring the 10% non-compliant devices into compliance

    Use Intune compliance policies and reports rather than additional licensing:

    1. Review tenant-wide compliance settings
    • In the Intune admin center, go to Endpoint security > Device compliance > Compliance policy settings.
    • Check Mark devices with no compliance policy assigned as:
      • If set to Not compliant, any device without a policy will be counted as noncompliant.
      • Adjust only if this aligns with the organization’s security posture.
    • Review Compliance status validity period (days) to ensure devices that haven’t checked in recently are handled as intended.
    1. Ensure every device type has an appropriate compliance policy
    • Create platform-specific compliance policies for each device type in scope (Windows, Android, iOS/iPadOS, macOS, etc.).
    • Assign these policies to the correct user or device groups so all managed devices are evaluated.
    • For Windows devices, the guidance includes requiring BitLocker, Secure Boot, TPM, firewall, antivirus, and antispyware where applicable.
    1. Use Intune reports to identify and remediate non-compliant devices
    • In the Intune admin center, use Reports > Device compliance > Policy compliance to see compliant vs noncompliant devices.
    • Use Devices > Monitor > Policies with noncompliant and error devices and Noncompliant devices to:
      • Identify which policies and settings are failing.
      • Drill into specific devices and remediate issues (for example, missing encryption, outdated OS, or threat level above allowed threshold).
    1. Integrate with Conditional Access (optional but recommended)
    • If Conditional Access is configured with Require device to be marked as compliant, Microsoft Entra ID uses the Intune compliance status to allow or block access.
    • Ensure Conditional Access and compliance policies are aligned so that once devices meet compliance rules, they are allowed access.
    1. Special device types (conference room, kiosk, IoT-like)
    • These devices can still be managed and evaluated by Intune if they run a supported OS and are enrolled.
    • Assign them to appropriate device groups and apply tailored compliance policies (for example, kiosk profiles with minimal requirements where justified).
    • There is no separate compliance license documented for these device categories; they are handled via the same Intune compliance framework.
    1. Third-party-managed devices (if applicable)
    • If some devices are managed by a third-party MDM, Intune can consume compliance signals from supported partners.
    • Those partners send compliance state to Intune and Microsoft Entra ID, and the combined signals can be used in Conditional Access.

    In summary, to “integrate” non-compliant devices, ensure they are enrolled, assigned appropriate compliance policies, and covered by tenant-wide compliance settings and reporting. No additional device-specific license beyond Microsoft 365 E5 is described in the provided documentation.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.