How to force immediate compliance status re-evaluation in Intune for faster Noncompliant detection during AutoHeal?

Vinit Kumar 10 Reputation points
2026-09-28T03:58:19.3933333+00:00

Hi Everyone,

 

We are building an AutoHeal solution using Microsoft Intune, where remediation scripts automatically fix non-compliant devices. As part of our testing, we need to intentionally break a compliance policy setting on a device (for example, disabling Windows Firewall) and verify that Intune reflects the Noncompliant status quickly so we can trigger the AutoHeal remediation.

 

The Problem:

After breaking a compliance setting and running a manual sync, the compliance status update in the Intune portal is inconsistent. Sometimes it reflects in 5–10 minutes, but other times it takes 30+ minutes or more.

 

What we have already tried:

• Clicking the Sync button from the Intune portal on the device page

• Running compliance sync via IME agent on the device:

IntuneWindowsAgent.exe intunemanagementextension://synccompliance

• Restarting the IntuneManagementExtension service on the device

• Running both portal Sync and IME sync together

 

Question:

Is there a reliable and faster way to force Intune to immediately re-evaluate and update the compliance status of a device after a compliance policy setting is changed, so the Noncompliant status reflects consistently within 2–3 minutes in the portal?

 

Any PowerShell commands, MDM sync triggers, scheduled task methods, or Intune portal actions would be greatly appreciated.

 

Thank you.

Microsoft Security | Intune | Compliance
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-28T03:58:41.7733333+00:00

    There is no documented way to force Intune compliance to update consistently within 2–3 minutes in the portal after a device becomes noncompliant.

    Supported behavior from the documentation:

    1. Devices check for policy updates every eight hours by default on Windows.
    2. A manual sync can be triggered from the device or through the Intune admin center.
    3. For supported Windows devices, Intune supports client-driven compliance evaluation, where certain local state changes can proactively request a compliance re-evaluation instead of waiting for the next scheduled check-in.
    4. Even with sync, full application and status update depend on setting complexity and device state.

    For the fastest supported path during testing:

    1. On the Windows device, open Company Portal.
    2. Go to Devices > Check Status to evaluate device settings and verify access.
    3. Go to Settings > Sync to immediately check for policy updates.
    4. After changing the compliance setting, allow time for Intune to process the new state, because portal update timing is not guaranteed to be immediate.

    If the goal is to avoid immediate access loss while testing AutoHeal, use a grace period in the compliance policy:

    1. Open the device compliance policy.
    2. Go to Properties > Actions for noncompliance.
    3. Select Mark device noncompliant.
    4. Enter a nonzero number in Schedule (days after noncompliance).

    That creates an InGracePeriod state before the device is marked fully NonCompliant.

    If the issue being tested is specifically firewall-related on Windows 10 devices and incorrect compliance is being reported, the documented workaround is:

    1. In the compliance policy, either configure a nonzero grace period under Actions for noncompliance, or
    2. Under System Security > Device Security, set Firewall to Not configured.
    3. Then ask users to manually sync their Windows devices.

    Based on the available documentation, no supported PowerShell command, IME command, scheduled task method, or portal action guarantees a consistent 2–3 minute compliance status update in Intune portal reporting.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.