Ensuring devices meet organizational security and compliance policies
Intune decides whether a device is compliant based on the device compliance policies that are configured and assigned. These policies are sets of rules and conditions (for example, system security, Defender, Microsoft Defender for Endpoint risk level) that the device must satisfy. The overall device compliance status is the evaluation result of all applicable compliance policies for that device.
Key points:
- How Intune determines compliance
- Device compliance policies are platform-specific rule sets assigned to users/devices.
- Each policy contains settings (for example, firewall, TPM, antivirus, antispyware, Defender real-time protection, Defender signatures, Microsoft Defender for Endpoint risk score).
- The device evaluates each setting and reports a per-setting status (Compliant, Not compliant, Error, etc.).
- The overall device compliance status is derived from all policies and settings that apply to that device. If any required setting is Not compliant (and no grace period applies), the device becomes Not compliant.
- If a setting remains in Error for more than seven days, the device becomes Not compliant (or In grace period if a grace period is configured).
- Windows Defender / Microsoft Defender Antivirus as compliance criteria Intune can use Microsoft Defender Antivirus state and signatures as compliance requirements when those settings are enabled in a Windows device compliance policy:
- Antivirus (general):
- If set to Require, Intune checks antivirus solutions registered with Windows Security Center (including Microsoft Defender). If antivirus is disabled or out of date, the device is noncompliant.
- Antispyware:
- If set to Require, Intune checks antispyware solutions registered with Windows Security Center. If antimalware is disabled or out of date, the device is noncompliant.
- Microsoft Defender Antimalware:
- If set to Require, Intune turns on Microsoft Defender Antimalware and prevents users from turning it off. If Defender is not running as required, the device is noncompliant.
- Microsoft Defender Antimalware minimum version:
- If a minimum version is configured, Defender must be at or above that version. Otherwise, the device is noncompliant.
- Microsoft Defender Antimalware security intelligence up-to-date:
- If set to Require, Defender security intelligence (virus signatures) must be up to date. If signatures are out of date, the device is noncompliant.
- Real-time protection:
- If set to Require, Defender real-time protection must be enabled. If it is disabled, the device is noncompliant.
- Microsoft Defender for Endpoint risk score as compliance criteria If Microsoft Defender for Endpoint integration is enabled and the setting “Require the device to be at or under the machine risk score” is configured, the Defender for Endpoint risk assessment becomes part of compliance:
- The maximum allowed threat level can be set to Clear, Low, Medium, or High.
- If the device’s risk level exceeds the configured maximum, the device is evaluated as noncompliant.
- Example impact for Network Access Control (NAC)
- If NAC relies on Intune’s overall compliance state, any of the above Defender-related settings configured as Require (and not satisfied) will cause the device to be Not compliant and therefore blocked by NAC.
- Conversely, if those settings are left as Not configured, Defender state/signatures are not considered for compliance.
References: