Forum Discussion

Ion Zubia's avatar
Ion Zubia
Brass Contributor
Mar 07, 2018

How to exclude specific machines from Intune compliance policy?

Hi,   I need a few virtual machines to be excluded from the Intune compliance policy, I thought that the following setup would be sufficient to accomplish this and be able to access corporate dat...
  • Oliver Kieselbach's avatar
    Oliver Kieselbach
    Mar 08, 2018

    Hi Ion,

     

    I totally understand and agree that this would be great to have. User assignment and exclusion of devices. This would solve this problem and many more I think. I don't see any other solution than using device groups in total for compliance policy. Gather your devices via a dynamic group and assign the compliance policy. But there is another side effect if you assign users compliance policies and devices compliance policies. When a user is now target of a policy and his device also, the overall status of compliance policy is not calculated as an logical AND it's an logical OR. let me give an example:

    user A -> user policy A

    user A uses device A and has device policy B

    then it might be like this:

    user policy A is evaluated as compliant and device policy B is evaluated as non-compliant. Now because of the logical OR the user will get IsCompliant=True

    So mixing is not a great idea. At the moment we need to decide to go for user assignments or device assignments imho. this leads to various restrictions.

    Best way imho is to exclude them from the Conditional Access policy...

     

    best,

    Oliver

Resources