Blog Post

Intune Customer Success
3 MIN READ

Support tip: Known issues in reporting and viewing compliance policies

Intune_Support_Team's avatar
Jun 30, 2022

The Intune team is aware of compliance reporting behavior in the Microsoft Endpoint Manager admin center that causes confusion among some of our customers. With this post, we’d like to make you aware of these issues while we work on providing better experiences in the future.

Compliance policy status is “Not applicable” on some devices when the settings actually are applicable

We are aware of an issue where targeting a device with a compliance policy that has one or more of the following settings enabled can cause the compliance policy to show a “Not applicable” status, even though the settings actually do apply:

  • Custom compliance (Windows 10 and later)
  • Require the device to be at or under the machine risk score (iOS/iPadOS, Android device administrator, Android Enterprise)
  • Require the device to be at or under the Device Threat Level (iOS/iPadOS, Android device administrator, Android Enterprise, Windows 10 and later)
  • Jailbroken devices (iOS/iPadOS)

Note: This issue does not occur if you include another setting in the same policy, such as a minimum or maximum OS version.

 

The reason this occurs is due to how reporting data is calculated. The reporting data for these settings may not be immediately reflected until the system has had a chance to process all of the reporting data, usually within 24 hours.


While this is a known issue, the compliance setting status should resolve itself within 24 hours. If it doesn’t resolve after 24 hours, ensure that the device configuration profile has been applied appropriately. We are working to fix this issue so that the correct compliance status is always shown.

Understanding device counts in the Setting compliance report

Compliance reports help you understand when devices fail to meet your compliance configurations and help you identify compliance-related issues in your organization. The Setting compliance report (Devices > Monitor > Setting compliance) displays the number of devices in each compliance state for each compliance setting within a compliance policy in your environment. So, you may notice the number of compliant devices listed doesn’t match the number of enrolled devices the policy has been applied to.

Setting compliance report in Microsoft Endpoint Manager admin center


The numbers in each column reflect the number of compliance records Intune has for each compliance setting. When multiple users check-in on the same device, multiple reporting records are captured for the same policy for each user. This occurs most often with devices shared among multiple users, such as desktop PCs.


We are working on improving reporting views, including the Setting compliance report, to only count each device once.

Refer to Monitor results of your device compliance policies in Microsoft Intune for more information on monitoring device compliance.

Some noncompliant devices don’t appear in the Retire noncompliant devices list

When a device becomes noncompliant to a policy, the device is added to the Noncompliant devices report and may be included in the Retire noncompliant devices list if the Retire the noncompliant device action for noncompliance is configured. While the report and list may appear similar, they have different purposes:

  • The Noncompliant devices report allows you to monitor and manage devices that have become noncompliant. Use this report to determine whether to troubleshoot specific devices or manage or update compliance policies.
  • The Retire noncompliant devices list shows devices where the Retire the noncompliant device action has been triggered. Use this list to review these devices and then use the buttons on this list to either retire the devices or restore them to their previous compliance state.

We are working on changes to make the purpose of the Retire noncompliant devices list clearer in the Endpoint Manager admin center.

 

We will continue to update this post as new information becomes available. If you have questions or comments for the Intune team, reply to this post or reach out to @IntuneSuppTeam on Twitter.

Updated Dec 19, 2023
Version 7.0
  • lav_kce's avatar
    lav_kce
    Brass Contributor

    Will there be any updates with regards to wrong reporting under the Security Baselines area? For instance, if you compare the information displayed under the overview section with the per setting status page, you will notice the disparity in the device counts.

     

     

     

    The other issue is that the device counts are not even close to accurate, as the total device count should be around approx. 1000 devices. 

    Also if we purge some of the stale entries as part of the clean-up process, The total device count doesn't go down and instead it retains it even after months.

  • Reza_Ameri's avatar
    Reza_Ameri
    Silver Contributor

    Thank you, I prefer to use one Microsoft Account for all Microsoft related tasks and switching from Microsoft Account to Twitter and so on is not very user friendly. Thank you for monitoring this forum and I will keep posting issues here.

  • Hi Reza_Ameri and akshayarendal, we welcome any questions or feedback on our blog posts directly in the comments or via private message to the Intune team on the Tech Community platform! We've also captured this for future consideration. Thanks for the feedback!

  • akshayarendal's avatar
    akshayarendal
    Copper Contributor

    Twitter is also banned in a few countries 😄 and may get banned in a few more countries looking at the ways they are treating themselves above the government and people. So it's indeed better to figure out better communication platforms 

  • Reza_Ameri's avatar
    Reza_Ameri
    Silver Contributor

    Just feedback, you shared a contact in Twitter.

    It would have been nice if you setup a communication platform inside this Microsoft Technical Community.

    Twitter is popular but not everyone is using it and we want to keep in touch with Microsoft using Microsoft Account.