Implement device compliance policies – Manage policies and profiles

Implement device compliance policies – Manage policies and profiles

Implement device compliance policies

Device compliance policies can be used with or without conditional access policies and achieve the following outcomes:

  • With conditional access Devices in compliance can access corporate resources. Devices that are not compliant will be blocked from accessing corporate resources.
  • Without conditional access Effectively, these policies evaluate the compliance status of a device only. Used alone, there are no access restrictions to corporate resources because of a compliance policy.

You can use compliance policies without conditional access policies to evaluate the status of your devices. You can report information relating to device platform characteristics, such as the following:

  • The number of devices that do not have compliance policies
  • The number of devices that are not encrypted
  • Whether devices are jailbroken or rooted
  • Threat agent status

A list of the device attributes that can be reported is shown in Table 2-2.

TABLE 2-2 Device data available in Microsoft Intune

DetailDescriptionPlatform
NameThe name of the device.Windows, iOS
Management NameThe device name used only in the console. Changing this name won’t change the name on the device.Windows, iOS
UDIDThe device’s Unique Device identifier.Windows, iOS
Intune Device IDA GUID that uniquely identifies the device.Windows, iOS
Serial NumberThe device’s serial number from the manufacturer.Windows, iOS
Shared DeviceIf Yes, the device is shared by more than one user.Windows, iOS
User Approved EnrollmentIf Yes, the device has user approved enrollment, which lets admins manage certain security settings on the device.Windows, iOS
Operating SystemThe operating system used on the device.Windows, iOS
Operating System VersionThe version of the operating system on the device.Windows, iOS
Operating System LanguageThe language set for the operating system on the device.Windows, iOS
Total Storage SpaceThe total storage space on the device (in gigabytes).Windows, iOS
Free Storage SpaceThe unused storage space on the device (in gigabytes).Windows, iOS
IMEIThe device’s International Mobile Equipment Identity.Windows, iOS, Android
MEIDThe device’s Mobile Equipment IDentifier.Windows, iOS, Android
ManufacturerThe manufacturer of the device.Windows, iOS, Android
ModelThe model of the device.Windows, iOS, Android
Phone NumberThe phone number assigned to the device.Windows, iOS, Android
Subscribe CarrierThe device’s wireless carrier.Windows, iOS, Android
Cellular TechnologyThe radio system used by the device.Windows, iOS, Android
WiFi MACThe device’s Media Access Control address.Windows, iOS, Android
ICCIDThe Integrated Circuit Card Identifier, which is a SIM card’s unique identification number.Windows, iOS, Android
Enrolled DateThe date and time the device was enrolled in Intune.Windows, iOS, Android
Last ContactThe date and time the device last connected to Intune.Windows, iOS, Android
Activation Lock Bypass CodeThe code that can be used to bypass the activation lock.Windows, iOS, Android
Azure AD RegisteredIf Yes, the device is registered with Azure Directory.Windows, iOS, Android
ComplianceThe device’s compliance state.Windows, iOS, Android
EAS ActivatedIf Yes, the device is synchronized with an Exchange mailbox.Windows, iOS, Android
EAS Activation IDThe device’s Exchange ActiveSync identifier.Windows, iOS, Android
SupervisedIf Yes, administrators have enhanced control over the device.Windows, iOS, Android
EncryptedIf Yes, the data stored on the device is encrypted.Windows, iOS, Android

Keiarra Mclemore

Learn More →

Leave a Reply

Your email address will not be published. Required fields are marked *