your device is not compliant" intune fix for users
User-facing fix for Intune non-compliant device warnings. Covers the Company Portal check, common remediation steps, and when to escalate. Use when users report the compliance warning. Not for admin policy configuration.
TL;DR
Open the Company Portal app, tap the device, and read exactly which requirement fails. Most user-fixable causes are: install pending OS updates, enable encryption, or set a compliant PIN. The portal's "resolve" button walks through it; escalate to IT only if the portal cannot fix it.
The error
Your device is not compliant. Contact your IT department.Steps
- Open the Company Portal app > Devices > the device. Expected: the failing requirement is listed in plain language (e.g. "encryption required").
- Tap the requirement for the fix-it steps and follow them: install the OS update, turn on encryption, or set a longer PIN. Expected: each item checks off.
- Sync the device: Company Portal > Settings > Sync. Expected: sync completes. Compliance re-evaluates after a sync, not instantly.
- Wait a few minutes and recheck compliance status in the portal. Expected: Compliant. If it still fails, note the exact requirement text for the ticket.
- If the portal cannot resolve it (e.g. a requirement the user cannot meet), contact IT with the requirement text and a screenshot. Expected: tier 2 investigates policy vs device.
When to use
- Users seeing the non-compliant warning
- Access blocked by Conditional Access due to compliance
When not to use
- Configuring compliance policies (admin task)
- Devices that should be compliant but are not (admin investigation)
Compatibility
- Intune Company Portal on iOS, Android, Windows, macOS
Variants
Compliance was fine yesterday
An OS update or policy change moved the goalposts; check what changed.
"Contact IT" with no details
The portal sometimes hides the reason; an admin can read the per-setting results in Intune.
Why it happens
Compliance is continuous, not one-time. Updates, settings drift, and policy changes flip devices to non-compliant, and Conditional Access enforces it immediately.
Edge cases
- Tell users not to remove the management profile to "fix" it; that breaks enrollment entirely.
- Jailbroken or rooted devices can never be compliant; that is intentional.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_wpxgAw9QFKfVIfOOnDBCbA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.