Ensuring devices meet organizational security and compliance policies
Intune device compliance is controlled by policies and tenant-wide compliance settings, not by separate per-device licenses beyond what is already included in Microsoft 365 E5.
Key points for the scenario:
- Licensing
- Microsoft 365 E5 already includes the necessary rights to use Intune and device compliance policies for supported platforms.
- There is no separate Intune “device license” required specifically for non-compliant devices, conference room systems, kiosks, or IoT-type hardware in the context of compliance reporting.
- Compliance is evaluated per device based on assigned policies and tenant compliance settings, not by an additional license type in the documentation provided.
- Why devices show as non-compliant
- Devices are marked compliant or noncompliant based on:
- Platform-specific compliance policies assigned to users/devices.
- Tenant-wide Compliance policy settings.
- If a device has no compliance policy assigned, its status depends on the tenant setting Mark devices with no compliance policy assigned as:
- Compliant (default) – devices without a compliance policy are treated as compliant.
- Not compliant – devices without a compliance policy are treated as noncompliant.
- When using Conditional Access with device compliance, the recommendation is to set Mark devices with no compliance policy assigned as to Not compliant so only confirmed-compliant devices can access resources.
- How to bring the 10% non-compliant devices into compliance
Use Intune compliance policies and reports rather than additional licensing:
- Review tenant-wide compliance settings
- In the Intune admin center, go to Endpoint security > Device compliance > Compliance policy settings.
- Check Mark devices with no compliance policy assigned as:
- If set to Not compliant, any device without a policy will be counted as noncompliant.
- Adjust only if this aligns with the organization’s security posture.
- Review Compliance status validity period (days) to ensure devices that haven’t checked in recently are handled as intended.
- Ensure every device type has an appropriate compliance policy
- Create platform-specific compliance policies for each device type in scope (Windows, Android, iOS/iPadOS, macOS, etc.).
- Assign these policies to the correct user or device groups so all managed devices are evaluated.
- For Windows devices, the guidance includes requiring BitLocker, Secure Boot, TPM, firewall, antivirus, and antispyware where applicable.
- Use Intune reports to identify and remediate non-compliant devices
- In the Intune admin center, use Reports > Device compliance > Policy compliance to see compliant vs noncompliant devices.
- Use Devices > Monitor > Policies with noncompliant and error devices and Noncompliant devices to:
- Identify which policies and settings are failing.
- Drill into specific devices and remediate issues (for example, missing encryption, outdated OS, or threat level above allowed threshold).
- Integrate with Conditional Access (optional but recommended)
- If Conditional Access is configured with Require device to be marked as compliant, Microsoft Entra ID uses the Intune compliance status to allow or block access.
- Ensure Conditional Access and compliance policies are aligned so that once devices meet compliance rules, they are allowed access.
- Special device types (conference room, kiosk, IoT-like)
- These devices can still be managed and evaluated by Intune if they run a supported OS and are enrolled.
- Assign them to appropriate device groups and apply tailored compliance policies (for example, kiosk profiles with minimal requirements where justified).
- There is no separate compliance license documented for these device categories; they are handled via the same Intune compliance framework.
- Third-party-managed devices (if applicable)
- If some devices are managed by a third-party MDM, Intune can consume compliance signals from supported partners.
- Those partners send compliance state to Intune and Microsoft Entra ID, and the combined signals can be used in Conditional Access.
In summary, to “integrate” non-compliant devices, ensure they are enrolled, assigned appropriate compliance policies, and covered by tenant-wide compliance settings and reporting. No additional device-specific license beyond Microsoft 365 E5 is described in the provided documentation.
References: