Forum Discussion
8i5-5i1
Apr 13, 2022Copper Contributor
How to block non-enrolled devices
We have recently migrated from Basic Security (O365) to Intune and we're trying to setup a policy to block iOS and Android devices if they are not enrolled with the company portal app. I setup a cond...
8i5-5i1
Copper Contributor
Hi Rudy, thanks for replying. We already have a conditional access policy to block legacy authentication - is this what you mean?
Apr 13, 2022
Mmmm okay so you have configured the compliance policies ....how did you configure the default compliance settings (mark devices without compliance policy as compliant or not compliant)
- 8i5-5i1Apr 13, 2022Copper ContributorI think that's it! We are still in the process of migrating to intune so we left that default compliance setting as : mark devices without compliance policy as compliant - we didn't want to risk blocking devices that are still on basic security.
I discovered the test device is still in the database listed as compliant because it used to belong to another user.
I'm not sure what the best course of action to use while we are migrating to intune - leave the default compliance setting in place or set it to "mark devices without compliance policy as not compliant"- Apr 13, 2022When you leave that setting to default... even people who only register their device (and not enrolling into Intune) can come "compliant" because there isn't a compliance policy targetted
https://docs.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started#compliance-policy-settings