Search all guides & tools⌘ / Ctrl KReader Hub
LAlite£14.99 · Buy on Gumroad ↗

Runbook 03 · 26 scenarios

Compliance and access

Find the failed compliance setting before changing Conditional Access.

Use these as diagnostic routes

The “start here” text identifies the first control plane and evidence to inspect. It does not replace change approval, safeguarding requirements, backup or a tested rollback route.

059

Device is non-compliant with no obvious reason

Start hereUse per-setting and non-compliant-device reports.

Intune compliance
060

Device has no compliance policy assigned

Start hereCheck group assignment, filters and tenant-wide compliance behaviour.

Intune compliance
061

Device remains Not evaluated

Start hereCheck recent check-in, assignment, platform support and evaluation state.

Intune compliance
062

Device is in grace period

Start hereIdentify the failed setting and the grace-period deadline.

Intune compliance
063

Compliance data is stale

Start hereSync and compare last contact with the evaluation timestamp.

Intune compliance
064

Minimum OS version requirement fails

Start hereUpdate Windows or correct an inappropriate minimum build.

Intune compliance
065

Maximum OS version policy blocks a newer build

Start hereCorrect the version range and validate the policy purpose.

Intune compliance
066

BitLocker encryption requirement fails

Start hereVerify encryption state, protector status and recovery-key escrow.

Intune compliance
067

Secure Boot requirement fails

Start hereCheck UEFI configuration and hardware capability.

Device firmware
068

TPM requirement fails

Start hereCheck TPM availability, readiness and firmware.

Device firmware
069

Code-integrity requirement fails

Start hereCheck Secure Boot, drivers and Windows security state.

Intune compliance
070

Antivirus or antispyware requirement fails

Start hereConfirm Defender or the approved security product is healthy.

Intune compliance
071

Real-time protection requirement fails

Start hereCheck Defender policy, services and competing antivirus.

Intune compliance
072

Firewall requirement fails

Start hereCheck active profiles, Group Policy and Intune policy conflicts.

Intune compliance
073

Password or PIN requirement fails

Start hereReview applicability and Windows Hello configuration.

Intune compliance
074

Defender device-risk requirement fails

Start hereInvestigate Defender alerts instead of weakening compliance.

Defender for Endpoint
075

Custom compliance script returns 65007

Start hereCorrect script execution and discovery output.

Intune compliance
076

Custom compliance reports missing setting 65008

Start hereReturn every required discovery value.

Intune compliance
077

Custom compliance returns invalid JSON 65009

Start hereValidate the compressed JSON payload.

Intune compliance
078

Custom compliance returns wrong datatype 65010

Start hereMatch discovery types to the compliance definition.

Intune compliance
079

Conditional Access blocks a remediated device

Start hereSync and allow compliance and token propagation before retesting.

Entra Conditional Access
080

Browser access works but desktop applications are blocked

Start hereCompare sign-in logs, client type, token and Conditional Access result.

Entra Conditional Access
081

Shared or kiosk device cannot satisfy user-based compliance

Start hereUse a deliberate device-based shared-device design.

Intune compliance
082

Stale devices distort compliance reports

Start hereUse a reviewed device clean-up and retention process.

Intune compliance
083

Non-compliance email is not received

Start hereCheck action configuration, user email attributes and timing.

Intune compliance
084

Default device compliance policy is misunderstood

Start hereSeparate built-in compliance checks from administrator-created policies.

Intune compliance

Search LAlite

A guide, a scenario or a checklist. Find it here.