Intune Android Compliance Error 65001 Despite Assigned Policy

SuzanneLarson-5000 0 Reputation points
2026-06-18T18:50:23.2733333+00:00

We have set up a device group in Entra for our Android single-app kiosks and assigned policies to that group. Each device is configuring correctly during setup.

However, when reviewing the devices in Intune:

  • In Devices > By Platform > Android, all devices show as Compliant.
  • But when opening an individual device, the Default Device Compliance Policy shows an Error:
    • “Has a compliance policy assigned – Error 65001 (Not applicable)”

This is confusing because the device group does have a default device compliance policy assigned.

Why is this error appearing on individual devices despite the policy being in place?

Microsoft Security | Intune | Microsoft Intune Android
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-18T18:50:36.4133333+00:00

    Error 65001 “Has a compliance policy assigned – Not applicable” is a per-policy evaluation result and doesn’t mean the device is generally noncompliant. It indicates that this specific built‑in/default compliance check is not applicable to how the device is enrolled or targeted, even though the device is still compliant under the actual device compliance policies that do apply.

    Key points from Intune behavior in this area:

    1. Overall device compliance vs. individual policy status
      • The Device compliance state shown in the main Android list (“Compliant”) reflects the device’s overall evaluation across all applicable device compliance policies.
      • Individual entries such as Default Device Compliance Policy can show Error / Not applicable without affecting the overall “Compliant” state, similar to how a device can be compliant for one setting/policy and noncompliant or not applicable for another.
      • As documented, the device compliance dashboard and reports aggregate results from all policies and settings; a device can be compliant overall while some policies or settings are not applicable or in error.
    2. “Not applicable” is expected when a policy or setting doesn’t apply
      • Intune uses Not applicable when a policy or setting cannot be evaluated for a given platform or scenario (for example, a policy type or rule that doesn’t apply to that device type or enrollment).
      • The troubleshooting guidance explicitly calls out Not Applicable as a normal state when a policy isn’t supported on a given platform or configuration. In such cases, the device can still be compliant based on other applicable policies.
    3. Why this shows on Android single‑app kiosk devices
      • Android single‑app kiosk devices are often enrolled in specialized modes (e.g., dedicated devices) where some tenant‑wide or default compliance checks do not apply in the same way as for user‑affinity devices.
      • The Default Device Compliance Policy entry is effectively acting like a built‑in, tenant‑wide compliance policy. If its specific “Has a compliance policy assigned” check cannot be meaningfully evaluated for that enrollment type or assignment model, Intune reports it as Error 65001 (Not applicable) while still allowing other device compliance policies to determine the overall state.
    4. Why the devices still show as Compliant in the Android list
      • The device has one or more device compliance policies that are applicable and successfully evaluated as compliant.
      • The overall Device compliance status tile and Android device list count a device as Compliant when at least one device compliance policy is successfully applied and no applicable policies are failing.
      • A single policy or setting showing Not applicable/Error does not override the compliant result from the policies that do apply.

    In short, the 65001 “Not applicable” error on the Default Device Compliance Policy is a per‑policy applicability/evaluation artifact and does not indicate a real compliance problem. The devices are compliant because the relevant Android compliance policies are applied and evaluated successfully; the default/tenant‑wide check simply doesn’t apply cleanly to this kiosk enrollment scenario.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    2 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.