How to check Intune device compliance before access is blocked

Tested on: Microsoft Intune admin center, Company Portal for Windows, and Microsoft Entra Conditional Access

An Intune compliance result answers a specific question: does the device currently meet the security requirements assigned by your organization? Checking that result before a user loses access is faster than troubleshooting an Outlook or Teams sign-in failure after Conditional Access has intervened.

There are three useful views. An administrator can inspect one device, use tenant-wide compliance reports, or ask the user to check access in Company Portal. Start with the view that matches your question.

Choose the compliance view that fits the problem

What you need to know Best place to check What it shows
Is one device compliant now? Intune admin center device record Overall state, assigned policies, and setting results
Which devices need attention? Intune compliance reports Fleet totals, noncompliant devices, missing policies, and setting trends
Can this user access work resources? Company Portal A user-facing access result and available remediation guidance

The overall device label is a starting point. It should lead you to the assigned policy and the setting that produced the result.

Check one device in the Intune admin center

Sign in to the Microsoft Intune admin center with a role that can read managed devices and compliance reports. Then follow this path:

  1. Open Devices, followed by All devices.
  2. Select the device you want to review.
  3. Open Device compliance.
  4. Review the assigned compliance policies and their current status.
  5. Open a policy result to inspect its individual setting results.

The setting view is the decisive screen. It separates a password, encryption, operating-system, firewall, antivirus, or device-risk requirement from the combined device result.

Confirm that you selected the active record

Duplicate or retired records can make an investigation misleading. Compare the device name, serial number, operating system, primary user, ownership, and last check-in time with the computer in front of the user. If two records have similar names, the most recently active record is usually the relevant one, but confirm its identity rather than deleting the older record during diagnosis.

A stale check-in means the displayed result might not reflect the device’s current configuration. Keep compliance evaluation and device contact separate until the timestamps show which came first.

Read the policy result before repairing the device

Open the policy and setting detail instead of guessing from the overall label. Not compliant means at least one evaluated requirement failed. In grace period means the device has not met every requirement but still has time before the configured deadline. Error means Intune could not complete an evaluation, so the error and timing need investigation.

If the result already identifies a failed requirement, use the setting-level repair path to work through that specific failure. This article stays focused on checking and interpreting the evidence rather than repeating the remediation workflow.

Review compliance across the tenant

Opening devices individually works for a support ticket, but reports are better for identifying scope. In the Intune admin center, go to Devices > Compliance > Monitor to review the compliance dashboard. For report-level detail, open Reports > Device compliance > Reports.

Useful views include Device compliance status, Devices without compliance, Policy compliance, and Setting compliance. Use the device report to find affected computers, the policy report to identify a problematic assignment, and the setting report to see whether one requirement is failing across many devices.

Separate unassigned devices from failed devices

A device without an applicable compliance policy is not the same as a device that failed a policy. Intune has a tenant setting that determines whether devices with no assigned compliance policy are treated as compliant or noncompliant. Review that setting before interpreting a large group of devices with no policy.

Newly enrolled devices can also appear as Not evaluated while Intune waits for an applicable policy or fresh information. Devices without user affinity, devices enrolled with a device enrollment manager account, and devices that have not checked in since a policy change can need additional context. Group these separately from confirmed failures so the compliance report remains actionable.

Let the user check access in Company Portal

Company Portal provides the user-facing view of the same access decision. On Windows, ask the user to open Company Portal, select Devices, choose the current device, and select Check access under Device status. The web portal offers a similar path through Devices > selected device > Check status.

The result can show that the device can access company resources, cannot access them, or can still access them while an action is required. When a remediation link is available, Company Portal can point the user toward the relevant setting. The check can take several minutes because the app contacts the service and evaluates the current requirements.

Intune device compliance checking workflow
Use the device record, setting result, and Company Portal access check as three separate pieces of evidence.

Do not repeatedly select Check access while the device is offline or before a required change has finished. A new check is useful after the device reconnects, a security control reaches its expected state, or an administrator corrects an assignment.

Interpret the result before taking action

Status Practical meaning Next decision
Compliant Assigned requirements currently pass Confirm the timestamp and investigate sign-in separately if access still fails
Not compliant At least one effective requirement failed Open the failed policy and setting
In grace period A requirement is unmet but the deadline has not expired Review the action and due date with the user
Not evaluated or Unknown Intune lacks a completed result in that view Check assignment, enrollment context, and recent device contact
Error A setting could not be evaluated Review the error, platform state, and reporting timeline

When several policies apply, Intune calculates one overall result from their individual states. The most severe effective state can determine the device result. That is why the per-policy and per-setting views matter more than a screenshot of the summary badge.

Know when compliance affects sign-in

Device compliance and Conditional Access are separate controls that work together. Intune calculates the device state. A Microsoft Entra Conditional Access policy can then require the device to be marked compliant before granting access to selected resources.

Before enabling that requirement broadly, Microsoft recommends testing it in report-only mode and protecting emergency access accounts from accidental lockout. Administrators should also confirm that at least one compliance policy exists and that a known device can reach a compliant state.

If antivirus health is the failing requirement, start by confirming the Windows security layer on the affected computer. If the device is compliant but sign-in still fails, review the Conditional Access result, user identity, target resource, and authentication requirements instead of changing the device policy.

Questions you might have

Why do the Intune admin center and Company Portal show different results?

The two views can refresh at different times and present different levels of detail. Confirm that both views refer to the same device record, then compare the last check-in and the latest Company Portal access check. If the difference persists, use the administrator’s policy and setting reports as the source for the compliance calculation.

Does Check access immediately force every policy to reevaluate?

Check access contacts the service and checks the device against current requirements, but the visible result can still depend on platform reporting and policy timing. Allow the device to complete required security or configuration changes before checking again. Repeated clicks do not replace a stable connection or a completed platform evaluation.

Why does a device show no compliance policy assigned?

The device or its user might not be included in the assigned group, an exclusion might take precedence, or the platform might not match the policy. Also review the tenant setting for devices without a compliance policy. Do not treat the absence of a policy as a failed security setting until assignment has been verified.

Can a compliant device still be blocked from Microsoft 365?

Yes. Conditional Access can require other controls such as multifactor authentication, an approved application, an authentication strength, or a permitted location. Open the sign-in details and identify the failed grant control before changing a compliance policy that already reports success.

Turn the status into a decision

Use the device record for one-machine detail, compliance reports for scope, and Company Portal for the user’s access view. Confirm the record and timestamp before interpreting the color or label. If a setting failed, follow that evidence into remediation; if compliance passed, move the investigation to Conditional Access or authentication. This keeps a simple status check from turning into unnecessary policy changes.