Skip to content

Commit 7def303

Browse files
committed
Content for linux compilance policy
1 parent 24e48b6 commit 7def303

4 files changed

Lines changed: 194 additions & 79 deletions

File tree

memdocs/intune/protect/compliance-policy-monitor.md

Lines changed: 20 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 08/24/2022
10+
ms.date: 10/17/2022
1111
ms.topic: how-to
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
@@ -36,6 +36,16 @@ Compliance reports help you understand when devices fail to meet your [complianc
3636
- The compliance status for an individual policy
3737
- Drill down into individual devices to view specific settings and policies that affect the device
3838

39+
This article applies to:
40+
41+
- Android device administrator
42+
- Android (AOSP) (preview)
43+
- Android Enterprise
44+
- iOS/iPadOS
45+
- Linux (Ubuntu Desktop, version 20.04 LTS)
46+
- macOS
47+
- Windows 10 and later
48+
3949
## Open the compliance dashboard
4050

4151
Open the **Intune Device compliance dashboard**:
@@ -72,11 +82,11 @@ Descriptions of the different device compliance policy states:
7282

7383
- **Compliant**: The device successfully applied one or more device compliance policy settings.
7484

75-
- **In-grace period:** The device is targeted with one or more device compliance policy settings. But, the user hasn't applied the policies yet. This status means the device is not-compliant, but it's in the grace period defined by the admin.
85+
- **In-grace period:** *(This status isn’t supported by Linux)* The device is targeted with one or more device compliance policy settings. But, the user hasn't applied the policies yet. This status means the device is not-compliant, but it's in the grace period defined by the admin.
7686

7787
- Learn more about [Actions for noncompliant devices](actions-for-noncompliance.md).
7888

79-
- **Not evaluated**: An initial state for newly enrolled devices. Other possible reasons for this state include:
89+
- **Not evaluated**: *(This status isn’t supported by Linux)* An initial state for newly enrolled devices. Other possible reasons for this state include:
8090

8191
- Devices that aren't assigned a compliance policy and don't have a trigger to check for compliance
8292
- Devices that haven't checked in since the compliance policy was last updated
@@ -87,12 +97,13 @@ Descriptions of the different device compliance policy states:
8797

8898
- **Not-compliant:** The device failed to apply one or more device compliance policy settings. Or, the user hasn't complied with the policies.
8999

90-
- **Device not synced:** The device failed to report its device compliance policy status because one of the following reasons:
100+
- **Device not synced:** *(This status isn’t supported by Linux)* The device failed to report its device compliance policy status because one of the following reasons:
91101

92102
- **Unknown**: The device is offline or failed to communicate with Intune or Azure AD for other reasons.
93-
94103
- **Error**: The device failed to communicate with Intune and Azure AD, and received an error message with the reason.
95104

105+
- **Checking status**: *(Applies only to Linux)* Intune is currently evaluating the devices compliance your organization’s policies.
106+
96107
> [!IMPORTANT]
97108
> Devices that are enrolled into Intune, but not targeted by any device compliance policies are included in this report under the **Compliant** bucket.
98109
@@ -103,12 +114,12 @@ When a setting for a compliance policy returns a value of **Error**, the complia
103114
##### Examples:
104115

105116
- A device is initially marked **Compliant**, but then a setting in one of the compliance policies targeted to the device reports **Error**. After three days, compliance evaluation completes successfully and the setting now reports **Not compliant**. The user can continue to use the device to access Conditional Access-protected resources within the first three days after the setting states changes to **Error**, but once the setting returns **Not compliant**, the device is marked **Not compliant** and this access is removed until the device becomes **Compliant** again.
106-
117+
107118
- A device is initially marked **Compliant**, but then a setting in one of the compliance policies targeted to the device reports **Error**. After three days, compliance evaluation completes successfully, the setting returns **Compliant**, and the device's compliance status becomes **Compliant**. The user is able to continue to access Conditional Access protected resources without interruption.
108119

109-
- A device is initially marked **Compliant**, but then a setting in one of the compliance policies targeted to the device reports **Error**. The user is able to access Conditional Access protected resources for seven days, but after seven days, the compliance setting still returns **Error**. At this point, the device becomes Not compliant immediately and the user loses access to the protected resources until the device becomes **Compliant** even if there's a grace period set for the applicable compliance policy.
120+
- A device is initially marked **Compliant**, but then a setting in one of the compliance policies targeted to the device reports **Error**. The user is able to access Conditional Access protected resources for seven days, but after seven days, the compliance setting still returns **Error**. At this point, the device becomes Not compliant immediately and the user loses access to the protected resources until the device becomes **Compliant**, even if there's a grace period set for the applicable compliance policy.
110121

111-
- A device is initially marked **Not compliant**, but then a setting in one of the compliance policies targeted to the device reports Error. After three days, compliance evaluation completes successfully, the setting returns **Compliant**, and the device's compliance status becomes **Compliant**. The user is prevented from accessing Conditional Access protected resources for the first three days (while the setting returns **Error**). Once the setting returns **Compliant** and the device is marked **Compliant**, the user can begin to access protected resources on the device.
122+
- A device is initially marked **Not compliant**, but then a setting in one of the compliance policies targeted to the device reports Error. After three days, compliance evaluation completes successfully, the setting returns **Compliant**, and the device's compliance status becomes **Compliant**. The user is prevented from accessing Conditional Access protected resources for the first three days (while the setting returns **Error**). Once the setting returns **Compliant** and the device is marked **Compliant**, the user can begin to access protected resources on the device.
112123

113124
#### Drill down for more details
114125

@@ -224,7 +235,4 @@ Policy conflicts can occur when multiple Intune policies are applied to a device
224235

225236
## Next steps
226237

227-
[Compliance policies overview](device-compliance-get-started.md)
228-
229-
230-
238+
[Compliance policies overview](device-compliance-get-started.md)

0 commit comments

Comments
 (0)