Devices · 7 min read

Microsoft Intune device health — what to check and why it matters

Published July 2026 · By M365Clarity

← All articles

Most Microsoft 365 tenants with Intune licences have it partially configured — devices are enrolled, but compliance policies are incomplete, Windows Update rings are missing, and personal devices are accessing company data with no app protection in place. This guide covers the seven areas that matter most.

1. Device compliance — what it actually means

A device compliance policy defines the minimum security bar a device must meet to access company resources. Common requirements include: minimum OS version, encryption enabled, PIN or password required, and no jailbreak or root. Devices that fail these checks are marked non-compliant.

The important part: a non-compliant device can still access email and files unless you have a Conditional Access policy that blocks non-compliant devices. Without that CA policy, compliance is advisory only — it tells you the device is out of spec but doesn't prevent it accessing anything.

Common gap: compliance policies exist but cover only Windows. iOS and Android devices — often personal devices using company email — have no policy and appear as compliant by default.

2. Windows Update for Business rings

Without WUfB rings, Windows devices update on Microsoft's schedule — which means your entire fleet could restart during business hours after a Patch Tuesday, and you have no ability to test updates on a pilot group before rolling them out broadly.

A basic ring structure looks like this:

The deferral on quality updates gives you 7 days to catch any problematic patches on your pilot group before they hit everyone. Feature update deferral gives you time to test major Windows releases. Neither prevents updates — they just give you a buffer.

Risk of no WUfB rings: devices update uncontrolled. A bad Patch Tuesday update can affect your entire fleet simultaneously with no warning and no rollback window.

3. BYOD and app protection (MAM)

Mobile Application Management (MAM) policies protect company data on personal devices without enrolling the device into Intune. They work at the app level — wrapping apps like Outlook, Teams, and OneDrive with controls that prevent data leaving those apps.

What MAM policies can do on personal devices:

Without MAM policies, a staff member using their personal iPhone for work email can copy company data to their personal notes, save attachments to iCloud, or share files via personal apps — and you have no visibility or control.

4. Configuration profile coverage gaps

Configuration profiles push settings to enrolled devices without user intervention. Five categories are worth checking:

Many tenants have some profiles configured but not all five. A device without a password policy profile is entirely dependent on the user setting a PIN themselves.

5. The lost device scenario

The most practical way to understand your Intune posture is to ask: if a company laptop was stolen from a coffee shop tonight, what would happen?

6. Autopilot

Autopilot is Microsoft's zero-touch provisioning system. When a new Windows device is powered on, Autopilot automatically joins it to your Azure AD, enrolls it in Intune, and applies your configuration profiles — without IT touching the device. The user signs in with their Microsoft 365 account and the device is ready.

Without Autopilot, someone from IT must manually set up each new device. For organisations with 20+ devices this becomes a significant time cost, and there's no guarantee devices are consistently configured.

How to check your Intune health in one scan

M365Clarity's Intune Health Report checks all of the above in a single scan — compliance percentage, WUfB ring count, MAM policy coverage for iOS and Android, config profile gaps, non-compliant device list, and Autopilot status. It also generates an AI-written scenario for exactly what would happen if a device was lost or stolen today given your current configuration.

Check your Intune health in 2 minutes

Connect your tenant, run a scan, and see your device management posture in plain English. Free plan available.

Scan your tenant free →

Related articles