ChatGPT Image Jun 29, 2026, 08_40_34 PM

Where risk meets compliance: The power of unified endpoint security

TL;DR

Device compliance, when integrated with Microsoft Intune and Defender for Endpoint, allows organisations to automatically block risky devices from accessing corporate resources. By linking device risk signals to Conditional Access, you can enforce real-time, zero-trust security and reduce exposure to threats.

Introduction

Device compliance should be at the top of any organisation’s cybersecurity priorities. It defines whether a device is trusted and more importantly, whether it should be allowed to access corporate data.

When combined with Microsoft Defender for Endpoint and Conditional Access, Microsoft Intune enables organisations to automatically block access from risky or non-compliant devices in real time.
 
Without this visibility and control, organisations risk exposing sensitive data to vulnerable devices—especially those running outdated operating systems or compromised by threats.

What is device compliance and why does it matter?

Device compliance ensures that endpoints meet defined security standards before accessing company resources.

For example, if a device is running an outdated OS, lacks required security configurations or is flagged as risky, it can be marked as non-compliant, and access can be restricted immediately.
 
Without a compliance baseline, organisations have:
  • No clear visibility into insecure devices
  • No way to enforce access control
  • Increased exposure to cyber threats

What is device risk in Defender for Endpoint?

Device risk is determined by Microsoft Defender for Endpoint based on:

  • Active alerts
  • Detected vulnerabilities
  • Suspicious or malicious activity

 

These alerts are visible in the Alerts page and are continuously updated through real-time telemetry.
 

However, what’s not new is Defender for Endpoint is preventing these threats in the device and making sure the device is safe by quarantining malware or going through the Automated Investigation and Resolution tasks if configured. 

Identifying risks in the device can vary from a user opening a malicious file to suspicious activities in the device identified by the Defender for Endpoint Behavioural monitoring and reporting it as an alert. 

The risk level reflects the overall risk assessment of the device based on combination of factors, including the types and severity of active alerts on the device. Resolving active alerts, approving remediation activities, and suppressing subsequent alerts can lower the risk level.

Below figures shows how Defender for Endpoint reports the device risk. 

Risk levels

Risk Levels explained below are determined by Defender for Endpoint. It takes the vulnerabilities, risks along with the behavioural analysis done by the machine learning capabilities in Defender XDR. It is important to note that you are required to setup the security polices in Defender and apply it to your devices. 

  • Clear/ Secure – No active threats
  • Low – Minor risks detected
  • Medium – Moderate threats present
  • High – Significant security risk

A real-life example

Before enforcing policies, it’s important to understand how risk evolves in real environments.

Common scenarios include:
  1. End-user devices used for browsing, email, Teams, and SaaS apps—where vulnerabilities are constantly being patched
  2. Phishing attacks, where users click malicious links that compromise the device

 

Defender for Endpoint provides real time telemetry about your device fleet. If any of your devices are vulnerable to the threats or the device reports as infected, this risk level is updated automatically.   

This change of risk levels will signal Microsoft Intune to change the compliance of your device which will signal Entra ID to trigger the necessary Conditional Access Policies. 

How Intune, Defender and Conditional Access work together

This is where unified endpoint security becomes powerful.

 
Here’s the flow:
 
  1. Defender for Endpoint detects a threat → increases device risk
  2. Microsoft Intune evaluates the device compliance
  3. Device is marked as non-compliant if risk exceeds threshold
  4. Microsoft Entra Conditional Access blocks access
  5. User regains access only after remediation

 

This integration ensures that:
  • Risk signals are acted on instantly
  • Access decisions are automated
  • Security is enforced consistently

The powerful role of Microsoft Intune

This is where Microsoft Intune comes into play.

Microsoft Intune enables organisations to:
  • Define compliance policies
  • Continuously evaluate device health
  • Trigger actions based on compliance status

 

When combined with Conditional Access:

  • Non-compliant devices are blocked from corporate resources
  • Access is only granted when risk levels are acceptable

Device compliance policy rules in Defender for Endpoint

Microsoft Intune device compliance policies now have rules for Defender for Endpoint risk levels,.

You can configure devices to:

  • Become non-compliant immediately if risk exceeds thresholds
  • Regain compliance only when risk is reduced

Combine this with the Conditional Access Policies. Access to corporate applications and data will be immediately stopped as the device now poses a risk due to detected threats discovered by Defender for Endpoint. Users will be able to access the resources as soon as the device risk level is secure/ clear. 

This requires the device to be at or under the machine risk score in-order to enforce the controls. Devices that exceed the provided score get marked as noncompliant. 

Compliance behaviour based on risk:

You define the acceptable risk level – anything beyond that triggers enforcement.

 

Configure Components 

To enable this integration:

  1. Devices must be enrolled in Microsoft Intune
  2. Devices must be onboarded to Defender for Endpoint
  3. Service connection between Intune and Defender must be configured
  4. Supported platforms:
    • Windows
    • iOS / iPadOS
    • Android

 

Microsoft Intune app protection policies

Beyond device compliance, App Protection Policies provide another layer of control.

These policies allow you to:
  • Block access to apps based on device risk
  • Protect corporate data even on unmanaged devices

 

Platforms supported:
  • Android
  • iOS / iPadOS
  • Windows

Further, Microsoft Intune App Protection Policies can be configured in order to block access to the apps in the policy scope. 

This policy can be configured in ‘App | Protection’.

Configure the conditional access policy

Conditional Access (CA) is the final enforcement layer.

Key capabilities:

  • Block access from non-compliant devices
  • Use device filters to target specific scenarios
  • Require devices to meet compliance before accessing apps

End-user experience:

  • Access is blocked when device risk is high
  • Users must remediate issues before regaining access

 

Setting it up:

Create the CA policy in-order to block access to corporate resources depending on the device compliance. 

At a glance, Entra ID devices page will show you the compliance signal. 

Use device filters in conditions 

When creating the Conditional Access policy, you can use the above compliance signal to make sure you are addressing the correct set of devices by setting a Device Filter in your policy. 

Set the grant action 

This will make sure the access to the resources are blocked until the device risk is remediated and marked as compliant. Which means the Device Risk needs to be clear or have to be at the given state. 

End-user experience with the conditional access policy enforcement

Notifications and visibility

IT Admins can configure notifications to:

  • Alert users when devices become non-compliant
  • Notify IT or helpdesk teams

 

Options include:
  • Email notifications to end users
  • Additional recipients (e.g. IT admins)

 

Setting it up:

Create notifications in ‘Compliance Policies’ and you’ll get notified when the devices are not compliant. 

Set the option  ‘Send email’ to ‘end user’ and select an additional user as well. This can be your IT admin or helpdesk email address. 

Remediation

To restore compliance and access:

  1. Remediate vulnerabilities (manually or automatically)
  2. Resolve active alerts on the device
  3. Reduce device risk level

 

Removing the device from policies may bypass enforcement – but does not remove the underlying threat.

Wrapping up

The ability to link real-time risk signals with automated access control is one of the biggest strengths of Microsoft’s security ecosystem.

By integrating Defender for Endpoint, Microsoft Intune, Conditional Access, organisations can:
  • Detect threats instantly
  • Enforce compliance automatically
  • Block risky devices in real time

 

Device compliance isn’t just a policy, it’s a critical control point for reducing risk and protecting corporate data.

More insights

Get started on the right path to cloud success today. Our Crew are standing by to answer your questions and get you up and running.