Cloud Security Stack
Architecture notes

Architecture

Intune device compliance that people can live with

Compliance policy is where Zero Trust becomes real or becomes theatre. The settings that matter, and the ones that only generate support tickets.

11 min read · Reviewed 22 August 2026 · Architecture notes from tenant builds.

Compliance is only meaningful if access depends on it

A compliance policy that reports non-compliance and does nothing is a dashboard. It becomes a control the moment Conditional Access requires a compliant device, and not before. Many estates run compliance policies for years without that link and believe they have device trust.

Check this first. If a non-compliant device can still reach email, the policy is decoration.

The settings that earn their place

01

Disk encryption

BitLocker or FileVault, enforced and with keys escrowed. This is the setting that turns a lost laptop from an incident into a form.

02

Operating system minimum version

Set it, and set it as a moving floor rather than a fixed number somebody has to remember to update. This is the one that actually drives patching.

03

Defender running and healthy

Real-time protection on, signatures current. Cheap to enforce and it catches the machine that has been quietly unprotected for months.

04

A grace period, deliberately chosen

Non-compliance should not lock someone out mid-meeting. A grace period of a day or two turns a support crisis into a notification, and it is the single setting that decides whether people accept the policy.

The settings that mostly generate tickets

Aggressive password complexity on top of an already-enforced platform policy, screen lock timeouts measured in seconds, and jailbreak detection on corporate-owned iOS that is already supervised. Each of these has a defensible rationale and a poor ratio of risk reduced to goodwill spent.

Goodwill is finite in a compliance rollout. Spend it on encryption and patching, which is where the risk actually is.

The one to test before enforcement

Take one device, mark it non-compliant deliberately, and walk through exactly what the user sees and what they can still reach. Most organisations discover something surprising, usually that a critical business application was never in scope of the Conditional Access policy at all.

The verdict

Our pick

Encryption, OS floor, Defender health, and a grace period

Four settings that map to real risk, are cheap to enforce, and survive contact with users. Everything else is a negotiation.

Who should skip

Do not enforce compliance-based access before you have tested the non-compliant experience. That is how a Monday morning becomes an outage.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.