Ensuring devices meet organizational security and compliance policies
There is no documented way to force Intune compliance to update consistently within 2–3 minutes in the portal after a device becomes noncompliant.
Supported behavior from the documentation:
- Devices check for policy updates every eight hours by default on Windows.
- A manual sync can be triggered from the device or through the Intune admin center.
- For supported Windows devices, Intune supports client-driven compliance evaluation, where certain local state changes can proactively request a compliance re-evaluation instead of waiting for the next scheduled check-in.
- Even with sync, full application and status update depend on setting complexity and device state.
For the fastest supported path during testing:
- On the Windows device, open Company Portal.
- Go to Devices > Check Status to evaluate device settings and verify access.
- Go to Settings > Sync to immediately check for policy updates.
- After changing the compliance setting, allow time for Intune to process the new state, because portal update timing is not guaranteed to be immediate.
If the goal is to avoid immediate access loss while testing AutoHeal, use a grace period in the compliance policy:
- Open the device compliance policy.
- Go to Properties > Actions for noncompliance.
- Select Mark device noncompliant.
- Enter a nonzero number in Schedule (days after noncompliance).
That creates an InGracePeriod state before the device is marked fully NonCompliant.
If the issue being tested is specifically firewall-related on Windows 10 devices and incorrect compliance is being reported, the documented workaround is:
- In the compliance policy, either configure a nonzero grace period under Actions for noncompliance, or
- Under System Security > Device Security, set Firewall to Not configured.
- Then ask users to manually sync their Windows devices.
Based on the available documentation, no supported PowerShell command, IME command, scheduled task method, or portal action guarantees a consistent 2–3 minute compliance status update in Intune portal reporting.