intune compliance policy blocking new devices
Fixes Intune compliance policies incorrectly marking new devices non-compliant. Covers policy evaluation timing, common failing settings, and grace periods. Use when fresh enrollments show non-compliant. Not for genuinely non-compliant devices.
TL;DR
Give compliance evaluation time (up to 8 hours on first enrollment), then check exactly which setting fails in Intune > Devices > the device > Device compliance. New devices usually fail on encryption or OS version checks that resolve once policies fully apply; use a grace period rather than loosening the policy.
The error
Device is not compliant. (On a freshly enrolled device that should pass.)Steps
- Wait and recheck: compliance evaluation can take hours on first enrollment. Expected: eventually compliant. Do not start changing policies in the first hour.
- Open Intune > Devices > the device > Device compliance to see the per-setting results. Expected: the failing setting is named (e.g. encryption, password, OS version).
- For encryption failures: confirm BitLocker/FileVault actually enabled; the policy may have evaluated before encryption finished. Expected: encryption completes, then compliance flips.
- For OS version failures: the device may need an update the policy requires. Expected: update applied. Alternatively scope the policy to exclude pending-update devices temporarily.
- Set a compliance grace period (Intune > Compliance policies > actions for noncompliance > grace period) so new devices get time before access is cut. Expected: fewer false blocks.
When to use
- New enrollments flagged non-compliant
- Compliance blocking Conditional Access for new users
When not to use
- Devices that are genuinely out of compliance
- Compliance working as intended
Compatibility
- Microsoft Intune; iOS/Android/Windows/macOS
Variants
Compliance flaps
The device drifts in and out; usually an intermittent check like jailbreak detection or a flaky encryption report.
One platform always fails
The compliance policy settings for that platform are stricter than the fleet can meet; review them.
Why it happens
Compliance is evaluated against the device's reported state, which lags reality on fresh enrollments. Policies written for steady-state devices punish new ones during the gap.
Edge cases
- Do not mark the policy "not configured" to fix this; use the grace period.
- Document the expected evaluation delay in the enrollment guide.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_pW6xMZJkazulkJV6cdouGA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.