---
title: "Prof-IT Intune Device Compliance"
description: "All devices should be compliance before company resources can be accessed. The compliance policies include the following: 1. Device Encryption 2. Windows Firewall status 3. Defender For Endpoint status & threat level 4. Minimum versions for iOS, Android, and Windows…"
url: "https://prof-it.services/docs/prof-it-intune-device-compliance/"
updated: "2025-02-15"
category: Admin Manuals
---

# Prof-IT Intune Device Compliance

All devices should be compliance before company resources can be accessed. The compliance policies include the following:

1. Device Encryption
2. Windows Firewall status
3. Defender For Endpoint status & threat level
4. Minimum versions for iOS, Android, and Windows
5. Windows TPM & Secure Boot

Compliance status for all devices can be verified on [Devices - Microsoft Intune admin center](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMenu/~/allDevices)
Click on the device you want to verify, Device compliance.

![](/wp-content/uploads/2024/03/image-6-1024x593.png)
This indicates an issue with the TPM Bitlocker & Secure Boot policy. If you double click it, it will show the per-settings errors.

![](/wp-content/uploads/2024/03/image-7-1024x484.png)
Per-setting compliance policy errors.

## Common issues

**Defender for Endpoint status** can be an issue if there is a third-part AV installed. Uninstall all that you can find.

**Defender for Endpoint threat level** - compliance issues regarding this should be taken verry seriously as it could indicate there is a threat on the device. Review incidents alerts, and the device on [Security & Compliance (microsoft.com)](https://security.microsoft.com/)

**BitLocker** will be auto enabled, recovery keys will be saved in Entra ID. Policies do require a certain device encryption cryptography. Should there be any conflicts, it's often enough to decrypt the drive, and enable encryption again.

**Secure Boot** should always be enabled. Follow these instructions to enable in case it isn't. It does often require entering the Bios settings, facetiming with the user could be usefull.
[Windows 11 and Secure Boot - Microsoft Support](https://support.microsoft.com/en-us/windows/windows-11-and-secure-boot-a8ff1202-c0d9-42f5-940f-843abef64fad)

**TPM** needs to be enabled as well. It also requires access to Bios if it isn't enabled. There is also TPM.MSC that can be used to configure and verify status.
[Enable TPM 2.0 on your PC - Microsoft Support](https://support.microsoft.com/en-us/windows/enable-tpm-2-0-on-your-pc-1fd5a332-360d-4f46-a1e7-ae6b0c90645c)
