Chapter materials
Before we begin configuring our policies, there is one setting that we want to configure for the tenant that tells Intune what to do with devices that do not have any compliance policies assigned.
For this, navigate to Devices and then Compliance. Then, click on Compliance policy settings.
We have two settings here:
- Mark devices with no compliance policy assigned as: A device without a policy assigned is a potential security risk as it could potentially be non-compliant with multiple settings. The best practice is always to set this to non-compliant.
- Compliance status validity period (days): This sets how long you will accept a prior status report – put another way, if a device has not checked into Intune, after how many days should it be flagged as non-compliant? At a very basic level, consider Windows updates; if a machine has not been seen for 30 days or more, assume it is missing at least one set of updates, possibly including antivirus...