If you’re managing devices with Microsoft Intune and notice that some are displaying “not evaluated” for compliance policies, it can be a bit confusing and concerning. This issue often indicates that the device hasn’t been properly assessed against your organization’s compliance standards, which can lead to uncertainty about security and management status.
Fortunately, this isn’t usually a major problem and can often be resolved with a few straightforward troubleshooting steps. Understanding why your Intune compliance status shows as “not evaluated” is the first step toward fixing the issue and ensuring your devices are properly monitored and secured.
In this article, we’ll explore common causes behind Intune device compliance not being evaluated and provide practical solutions to get your devices back on track. Whether it’s a policy configuration issue, synchronization problem, or something else, you’ll find clear guidance to help you resolve the problem efficiently and confidently.
By addressing these issues, you can maintain a healthier device environment, improve compliance reporting accuracy, and ensure your organization’s security policies are effectively enforced across all managed devices.
Understanding the “Not Evaluated” Status in Intune
Have you ever wondered why some devices show a “not evaluated” status in Intune, even after applying compliance policies? This status can be confusing, especially when you expect immediate feedback on device health. To get to the root of the issue, it’s essential to understand what this status truly signifies and how it impacts your device management.
What Does “Not Evaluated” Mean for Compliance?
When a device displays “not evaluated”, it indicates that the device has not yet been assessed against your organization’s compliance policies. Essentially, the device hasn’t gone through the evaluation process, so its compliance status remains unknown. This can happen for various reasons, such as recent enrollment, delayed synchronization, or policy misconfigurations.
In practical terms, a “not evaluated” status means you can’t confidently determine if the device meets security standards or if it’s compliant with policies like encryption, password complexity, or OS version. This uncertainty can pose risks, especially if the device is used for sensitive tasks.
Common Reasons Behind Intune Compliance Not Evaluated
Several factors can lead to a device remaining in the “not evaluated” state. Recognizing these causes helps in troubleshooting effectively. Some common reasons include:
- Device Enrollment Delay: Newly enrolled devices may take some time to be evaluated, especially if policies haven’t been pushed or synchronized yet.
- Synchronization Issues: Devices that haven’t recently synced with Intune may not have evaluated their compliance status. Regular syncs are crucial for timely assessments.
- Policy Misconfiguration: Incorrect or incomplete policy deployment can prevent devices from properly evaluating compliance.
- Network Connectivity Problems: Devices offline or experiencing network issues might not communicate with Intune servers, delaying evaluation.
- Device State or OS Issues: Outdated OS versions or device errors can interfere with the evaluation process.
Understanding these causes allows you to target your troubleshooting efforts more precisely, saving time and reducing frustration.
Impact of “Not Evaluated” on Device Management and Security
A device stuck in the “not evaluated” status can have several implications. First, it hampers your ability to enforce compliance policies effectively. Without a clear compliance status, you might unknowingly allow non-compliant devices to access corporate resources, exposing your organization to security risks.
Moreover, compliance reports become less reliable, making it harder to maintain a comprehensive view of your device fleet’s health. This can affect your organization’s overall security posture and compliance audits. In some cases, automated policies that rely on compliance status—like conditional access—may not function as intended, leading to potential security gaps.
In my experience, addressing the root causes of “not evaluated” statuses promptly not only restores accurate compliance reporting but also reinforces your organization’s security framework. Ensuring devices are evaluated regularly and correctly is a cornerstone of effective device management in Intune.
Troubleshooting Intune Policy Issues Causing “Not Evaluated”
Ever wondered why some devices remain stuck in the “not evaluated” state despite being enrolled and seemingly configured correctly? Often, the root causes lie within your policy assignments and device connectivity. Let’s explore how to identify and resolve these common issues to get your devices evaluated properly.
Verifying Policy Assignments and Scope
The first step is to confirm that your compliance policies are correctly assigned to the intended groups or devices. Sometimes, a simple misconfiguration can prevent a device from being evaluated.
Begin by checking in the Microsoft Endpoint Manager admin center whether the policies are assigned to the correct device groups. Ensure that the device in question is part of those groups. If policies are assigned but not targeted correctly, the device might not receive or evaluate the policies at all.
Additionally, verify that the policies themselves are active and properly configured. A common mistake is having policies in a draft or disabled state, which prevents evaluation. Remember, policy scope and assignment are crucial for proper device assessment.
Ensuring Device Connectivity and Enrollment Status
Connectivity issues are often overlooked but are critical for successful policy evaluation. Devices need to communicate with the Intune service regularly to receive updates and perform compliance checks.
Check the device’s network connection. Is it connected to the internet? Are there any firewall or VPN restrictions blocking communication? If the device is offline or has network issues, it won’t be able to sync with Intune, resulting in a “not evaluated” status.
Furthermore, confirm the device’s enrollment status. Sometimes, enrollment may be incomplete or corrupted, especially if there were errors during initial setup. You can verify this by navigating to the device’s details in Endpoint Manager. If enrollment is faulty, re-enrollment might be necessary to restore proper evaluation.
Checking for Conflicting or Outdated Policies
Sometimes, conflicting policies or outdated configurations can interfere with the evaluation process. For example, if multiple policies target the same setting but with different configurations, devices may not evaluate correctly.
Review your policy set for overlaps or conflicts. Use the Policy Conflict Detection feature in Endpoint Manager to identify issues. Also, ensure that your policies are up to date. Outdated policies might not be compatible with the current device OS or management framework, leading to evaluation failures.
In some cases, removing conflicting policies and reapplying the correct ones can resolve the “not evaluated” status. Regularly auditing your policies helps maintain a clean and effective management environment, reducing the chances of evaluation issues.
By systematically verifying policy assignments, ensuring device connectivity, and resolving policy conflicts, you can significantly improve the likelihood of your devices being evaluated correctly. These steps, combined with ongoing monitoring, help maintain a healthy device management ecosystem and keep your compliance reports accurate.
Steps to Resolve Intune Device Showing “Not Evaluated”
Have you ever wondered what actionable steps you can take when a device remains stuck in the “not evaluated” status? Sometimes, the solution isn’t immediately obvious, but with a systematic approach, you can usually resolve the issue quickly. Let’s explore some practical methods I’ve found effective in fixing intune compliance not evaluated problems.
Refreshing Device Compliance Data Manually
One of the simplest yet often overlooked steps is to manually prompt the device to re-evaluate its compliance status. Devices periodically check in with Intune, but sometimes, a manual refresh is necessary. This is especially true if recent policy changes or updates haven’t been reflected yet.
On Windows devices, you can trigger a sync by opening the Company Portal app or using the Settings > Accounts > Access work or school section, then selecting your account and clicking Sync. For mobile devices, a simple restart or opening the Intune app can also prompt a re-evaluation.
Additionally, in the Microsoft Endpoint Manager admin center, you can force a device sync remotely. Navigate to the device’s details, then click Sync. This action requests the device to re-evaluate its compliance policies immediately. Regular syncs are vital, especially after deploying new policies or updates.
Re-enrolling Devices and Updating Policies
If manual syncs don’t resolve the issue, re-enrollment can often do the trick. Sometimes, a device’s enrollment becomes corrupted or incomplete, preventing proper evaluation. Re-enrollment essentially resets the device’s management profile, giving it a fresh start.
This process involves removing the device from management, then re-enrolling it following your standard enrollment procedures. Before doing so, ensure that the device is backed up if necessary, and inform users about the re-enrollment process to avoid disruptions.
Alongside re-enrollment, reviewing and updating your policies is essential. Make sure all policies are correctly assigned, enabled, and compatible with your device OS versions. Sometimes, outdated or conflicting policies can cause evaluation failures. According to Microsoft, proper policy management is key to avoiding such issues.
Using Troubleshooting Tools and Logs for Deeper Insight
When the above steps don’t yield results, diving into logs and troubleshooting tools becomes necessary. The Intune Troubleshooting Portal offers valuable insights into device status and compliance evaluation history.
Access the portal and select the affected device. Review the Device diagnostics and Compliance reports for errors or warnings. These logs can reveal underlying problems such as network issues, policy conflicts, or enrollment errors.
For more detailed analysis, you might also review device logs directly on the device itself. On Windows, Event Viewer logs can provide clues about communication failures or policy application errors. On mobile devices, check for error messages within the device management apps.
By systematically leveraging these troubleshooting tools, you can identify root causes that might not be immediately obvious. This proactive approach often saves time and prevents recurring issues, ensuring your devices stay compliant and evaluated properly.
In my experience, combining these steps—manual refresh, re-enrollment, and deep log analysis—creates a robust strategy to resolve intune compliance not evaluated issues. Staying proactive and methodical makes all the difference in maintaining a healthy, compliant device environment.
Ensuring Accurate Compliance Evaluation for a Secure Device Environment
Addressing the “not evaluated” status in Intune is essential for maintaining a secure and compliant device fleet. By understanding the underlying causes—such as policy misconfigurations, connectivity issues, or enrollment problems—you can take targeted actions to resolve the issue effectively.
Implementing steps like manual device syncs, re-enrolling devices, and leveraging troubleshooting tools helps ensure devices are properly evaluated and their compliance statuses accurately reported. These proactive measures not only improve security posture but also streamline device management processes.
Ultimately, staying vigilant and methodical in your approach allows you to quickly identify and fix policy or connectivity issues, ensuring your organization’s devices remain compliant and secure. A consistent focus on these best practices empowers you to maintain a healthier device environment and confidence in your compliance reporting.