Implement compliance policies using Intune Flashcards

1
Q

What are the 2 areas in Intune regarding compliance policies

A

Compliance policy settings
&
device compliance policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are compliance policy settings?

A
  • tenant wide configuration
  • built in compliance policy that every device receives
  • establishes how compliance policy works in intune environment: spcifically, how to treat a device without explicit compliance policy assigned
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a device compliance policy?

A

discrete set of **platform-specific rules and settings **
deployed to group of users or devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 2 prerequisites to deploy a compliance policy (setting or device)?

A
  • Entra ID P1 or P2
  • Intune license for each user/device
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In intunes, where do you go to manage Compliance policy settings?

A

In Endpoint security > Device compliance > Compliance policies > Compliance policy settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 2 settings you can manage in compliance policy settings?

A
  • Mark devices with no compliance policy assigned as : Compliant (default) / not compliant
  • compliance status validity period : period on which devices must successfully report on all their received compliance policy. After that, marked as not compliant
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Where can you also set up or review compliance settings or the device compliance policies ?

A

In Devices > Under Manage devices > compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the key rule when you have several platform in your organization and you want to implement device compliance policies?

A

1 separate policy for each platform
Each device platform is different, so device compliance settings are different

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

List the 7 steps to create a device compliance policy

A

Step 1 : Go to Devices > Under Manage devices, select Compliance > Create policy.

Step 2 : Select a Platform for this policy from the following options:
Then select Create to open the configuration page.

Step 3 : On the Basics tab, enter a Name + Description for the policy.

Step 4 : On the Compliance settings tab, expand the available categories, and configure settings for your policy.
Optionally, you can add custom settings for Linux - Uuntu and Windows 10 & later if you already uploaded a detection script and have ready a JSON file that defines the settings

Step 5 : On the Actions for noncompliance tab, select a sequence of actions to apply automatically to devices that don’t meet this compliance policy.

Step 6 : On the Assignments tab, assign the policy to your groups. For Linux, you can choose only device groups

Step 7 : Review + create

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

On which platform can you create a device compliance policy?

A

Android device administrator
Android (AOSP)
Android Enterprise
iOS/iPadOS
Linux - (Ubuntu Desktop, version 20.04 LTS and 22.04 LTS, RedHat Enterprise Linux 8, or RedHat Enterprise Linux 9)
macOS
Windows 10 and later
Windows 8.1 and later

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is resulting compliance status?

A

If a device has multiple compliance policies, and the device has different compliance statuses for two or more of the assigned compliance policies, then a single resulting compliance status is assigned.
This assignment is based on a conceptual severity level assigned to each compliance status.
When a device has multiple compliance policies, then the highest severity level of all the policies is assigned to that device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the default action for noncompliance in device compliance policies?

A

Mark device noncompliant with a schedule of zero days

This means Intune immediately marks the device as noncompliant when it detects a noncompliance issue.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What happens when a device is marked as noncompliant?

A

Microsoft Entra Conditional Access can block the device

This action prevents access to resources until compliance is achieved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the purpose of configuring Actions for noncompliance?

A

Gain flexibility to decide actions for noncompliant devices and their timing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What can an organization choose regarding the blocking of a noncompliant device?

A

Not block the device immediately and provide a grace period

This gives users time to become compliant before any actions are taken.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What determines when an action for noncompliance takes effect?

A

A schedule defined in days after the device is marked as noncompliant

Organizations can set specific timelines for compliance actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Can multiple instances of an action be configured in a policy?

A

Yes

This allows the action to run again at a later scheduled time if the device remains noncompliant.

18
Q

Are all actions available for all platforms?

A

No

Availability of actions may vary depending on the platform being used.

19
Q

What is the default action taken for noncompliant devices?

A

Mark device non-compliant immediately.

This default action has a schedule of zero (0) days.

20
Q

What are the 4 available actions for non compliance?

A
  • Mark device non-compliant
  • Send email to end user
  • Remotely lock the noncompliant device
  • Send push notification to end user
21
Q

What action sends an email notification to the user regarding noncompliance?

A

Send email to end user.

This action includes details about the noncompliant device in the email notification.

22
Q

What must be created before assigning a notification message template for email notifications?

A

A notification message template.

The template can be customized with locale, subject, message body, and company information.

23
Q

What happens if no email address is defined in the user’s profile?

A

Intune doesn’t send a notification email.

Intune uses the email address defined in the end user’s profile.

24
Q

What must the user do when the noncompliant device has been remotely locked bbecause of noncompliant device action?

A

The user must enter a PIN or password to unlock the device.

25
Which 5 platforms support the action to remotely lock a noncompliant device?
* Android device administrator * Android (AOSP) * Android Enterprise (Fully Managed, Dedicated, Corporate-Owned Work Profile, Personally Owned Work Profile, kiosk devices) * iOS/iPadOS * macOS | Not windows, not Linux
26
What occurs when a device is added to the retire list in Intune?
It is marked as a noncompliant device but not retired until an admin initiates retirement. ## Footnote Retirement removes all company data and the device from Intune management.
27
What 6 platforms support the action to add a device to the retire list?
* Android device administrator * Android (AOSP) * Android Enterprise (Fully Managed, Dedicated, Corporate-Owned Work Profile, Personally Owned Work Profile) * iOS/iPadOS * macOS * Windows 10/11 ## Footnote Devices are not retired until explicitly initiated by an administrator.
28
What options are available for managing the retire state of devices?
* Retire all devices * Clear all devices retire state * Clear selected devices retire state ## Footnote Clearing the retire state removes the device from the retire list until added again.
29
What action sends a push notification about noncompliance to a device?
Send push notification to end user. ## Footnote This notification is sent the first time a device checks in with Intune and is found noncompliant.
30
What 3 platforms support sending a push notification about noncompliance?
* Android device administrator * Android Enterprise (Fully Managed, Dedicated, Corporate-Owned Work Profile, Personally Owned Work Profile) * iOS/iPadOS ## Footnote The notification opens the Company Portal app or Intune app to provide details.
31
True or False: The message details about noncompliance in push notifications can be customized.
False. ## Footnote The details are generated by Intune and cannot be altered.
32
If you want to monitor your devices' compliance where do you go?
In Intune, **Devices** > **Compliance**, and then select the **Monitor** tab.
33
What are the 4 compliance status categories you can find in Devices > Compliance > Monitor?
* Compliant * In-grace period * Not evaluated * Not compliant
34
What does it mean when a device is compliant?
The device successfully applied one or more device compliance policy settings. ## Footnote Compliance indicates that the device meets the required settings as defined by the policy.
35
What is an in-grace period for a device?
The device is targeted with one or more device compliance policy settings but isn't yet compliant to all of them. ## Footnote This status often arises from users not applying compliant configurations, such as failing to meet password complexity requirements.
36
What does 'not evaluated' mean for a device?
The initial state for newly enrolled devices that haven't been checked for compliance. ## Footnote This can also occur if devices aren't assigned a compliance policy, haven't checked in since the policy was last updated, or lack user association.
37
What could cause a device to be in a 'not evaluated' state?
Possible reasons include: * Devices not assigned a compliance policy * Devices that haven't checked in since the last policy update * Devices not associated to a specific user ## Footnote Examples of devices not associated with a user include iOS/iPadOS devices from Apple's Device Enrollment Program and Android kiosk devices.
38
What does it mean when a device is 'not compliant'?
The device failed to apply one or more device compliance policy settings, or the user hasn't complied with the policies. ## Footnote Noncompliance indicates a failure to meet the established security or configuration requirements.
39
By default, when you select a policy, what does Intune dispaly ?
Intune opens the Monitor tab for that policy, where Intune displays: * **Device status** - A simple bar chart that identifies the basic compliance status for devices that receive this policy. * **View report** - A button you can select that opens the device status report where you can view deeper details about device compliance to this policy. * **Per-setting status** - A tile you can select that opens the per-setting status report for this policy.
40
Which other compliance reports are availabble in Devices > Monitor ?
* Noncompliant devices * Policy noncompliance
41
How Intune resolves policy conflicts ?
can occur when multiple Intune policies are applied to a device * **between settings from an Intune configuration policy and a compliance policy**, the **settings in the compliance policy take precedence over the settings in the configuration policy**. * If you have deployed **multiple** compliance policies, Intune uses the **most secure of these policies**.