Platform coverage
Compare Windows, iOS/iPadOS, Android, and macOS enrollment against the devices the organization actually issues or permits.
Independent IT security review
Compliance policy only protects what it can see. The review maps enrollment coverage, policy strictness, and what actually happens to a device that fails a check.
A well-designed compliance policy has no effect on a device that never enrolled. The review establishes which platforms and ownership types are actually inside Intune before judging the rules themselves.
Compare Windows, iOS/iPadOS, Android, and macOS enrollment against the devices the organization actually issues or permits.
Separate corporate-owned, BYOD, and unmanaged personal devices, since each supports a different compliance and privacy boundary.
Confirm whether automatic enrollment, user-driven enrollment, or manual registration is the deployed path, and where it can be skipped.
A policy can exist and still not block access anywhere. Compliance settings only function as a control when Conditional Access actually requires them.
Review encryption, minimum OS version, jailbreak/root detection, and password requirements against what the organization intends to require.
Confirm whether sign-in actually depends on compliance status, or whether the policy is evaluated without consequence.
Check compliance grace periods and retire actions so a device is not silently trusted during an extended non-compliant window.
A device marked non-compliant does not automatically lose access, notify anyone, or get remediated. The review traces the actual consequence.
Confirm whether non-compliance blocks mail, SharePoint, Teams, or other resources, or only appears in a report.
Check whether the device user or an administrator is actually notified when status changes.
Document how a user restores compliance and how long an exception can persist before review.
Compliance requirements should match what the organization can support and licence, not a generic best-practice template.
Confirm which compliance and Intune capabilities the current Microsoft 365 or EMS licence actually includes.
Match policy strictness to the support model available for exceptions, lost devices, and legitimate older hardware.
Record which settings are enforced, which are monitored only, and why-so the next reviewer inherits reasoning, not just a policy export.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.