Runbook 03 · 26 scenarios
Compliance and access
Find the failed compliance setting before changing Conditional Access.
The “start here” text identifies the first control plane and evidence to inspect. It does not replace change approval, safeguarding requirements, backup or a tested rollback route.
Device is non-compliant with no obvious reason
Start hereUse per-setting and non-compliant-device reports.
Intune complianceDevice has no compliance policy assigned
Start hereCheck group assignment, filters and tenant-wide compliance behaviour.
Intune complianceDevice remains Not evaluated
Start hereCheck recent check-in, assignment, platform support and evaluation state.
Intune complianceDevice is in grace period
Start hereIdentify the failed setting and the grace-period deadline.
Intune complianceCompliance data is stale
Start hereSync and compare last contact with the evaluation timestamp.
Intune complianceMinimum OS version requirement fails
Start hereUpdate Windows or correct an inappropriate minimum build.
Intune complianceMaximum OS version policy blocks a newer build
Start hereCorrect the version range and validate the policy purpose.
Intune complianceBitLocker encryption requirement fails
Start hereVerify encryption state, protector status and recovery-key escrow.
Intune complianceSecure Boot requirement fails
Start hereCheck UEFI configuration and hardware capability.
Device firmwareTPM requirement fails
Start hereCheck TPM availability, readiness and firmware.
Device firmwareCode-integrity requirement fails
Start hereCheck Secure Boot, drivers and Windows security state.
Intune complianceAntivirus or antispyware requirement fails
Start hereConfirm Defender or the approved security product is healthy.
Intune complianceReal-time protection requirement fails
Start hereCheck Defender policy, services and competing antivirus.
Intune complianceFirewall requirement fails
Start hereCheck active profiles, Group Policy and Intune policy conflicts.
Intune compliancePassword or PIN requirement fails
Start hereReview applicability and Windows Hello configuration.
Intune complianceDefender device-risk requirement fails
Start hereInvestigate Defender alerts instead of weakening compliance.
Defender for EndpointCustom compliance script returns 65007
Start hereCorrect script execution and discovery output.
Intune complianceCustom compliance reports missing setting 65008
Start hereReturn every required discovery value.
Intune complianceCustom compliance returns invalid JSON 65009
Start hereValidate the compressed JSON payload.
Intune complianceCustom compliance returns wrong datatype 65010
Start hereMatch discovery types to the compliance definition.
Intune complianceConditional Access blocks a remediated device
Start hereSync and allow compliance and token propagation before retesting.
Entra Conditional AccessBrowser access works but desktop applications are blocked
Start hereCompare sign-in logs, client type, token and Conditional Access result.
Entra Conditional AccessShared or kiosk device cannot satisfy user-based compliance
Start hereUse a deliberate device-based shared-device design.
Intune complianceStale devices distort compliance reports
Start hereUse a reviewed device clean-up and retention process.
Intune complianceNon-compliance email is not received
Start hereCheck action configuration, user email attributes and timing.
Intune complianceDefault device compliance policy is misunderstood
Start hereSeparate built-in compliance checks from administrator-created policies.
Intune compliance