Architecture
Intune device compliance that people can live with
Compliance policy is where Zero Trust becomes real or becomes theatre. The settings that matter, and the ones that only generate support tickets.
Compliance is only meaningful if access depends on it
A compliance policy that reports non-compliance and does nothing is a dashboard. It becomes a control the moment Conditional Access requires a compliant device, and not before. Many estates run compliance policies for years without that link and believe they have device trust.
Check this first. If a non-compliant device can still reach email, the policy is decoration.
The settings that earn their place
Disk encryption
BitLocker or FileVault, enforced and with keys escrowed. This is the setting that turns a lost laptop from an incident into a form.
Operating system minimum version
Set it, and set it as a moving floor rather than a fixed number somebody has to remember to update. This is the one that actually drives patching.
Defender running and healthy
Real-time protection on, signatures current. Cheap to enforce and it catches the machine that has been quietly unprotected for months.
A grace period, deliberately chosen
Non-compliance should not lock someone out mid-meeting. A grace period of a day or two turns a support crisis into a notification, and it is the single setting that decides whether people accept the policy.
The settings that mostly generate tickets
Aggressive password complexity on top of an already-enforced platform policy, screen lock timeouts measured in seconds, and jailbreak detection on corporate-owned iOS that is already supervised. Each of these has a defensible rationale and a poor ratio of risk reduced to goodwill spent.
Goodwill is finite in a compliance rollout. Spend it on encryption and patching, which is where the risk actually is.
The one to test before enforcement
Take one device, mark it non-compliant deliberately, and walk through exactly what the user sees and what they can still reach. Most organisations discover something surprising, usually that a critical business application was never in scope of the Conditional Access policy at all.
The verdict
Encryption, OS floor, Defender health, and a grace period
Four settings that map to real risk, are cheap to enforce, and survive contact with users. Everything else is a negotiation.
Do not enforce compliance-based access before you have tested the non-compliant experience. That is how a Monday morning becomes an outage.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.