How to Configure Android Compliance Policies in Microsoft Intune

Key Takeaways

  • Strengthen organizational security by ensuring only compliant Android devices can access corporate resources.
  • Enforce password, encryption, and device security requirements to protect sensitive business data.
  • Improve endpoint compliance by defining operating system, security patch, and device health requirements.
  • Monitor compliance status and quickly identify noncompliant devices for faster remediation.

Let’s discuss How to Configure Android Compliance Policies in Microsoft Intune. This post will provide more details about planning and implementing the policy. Intune compliance policies are the first step of the protection before giving access to corporate apps and data. Planning and designing compliance policies for Android devices is essential as Android is more vulnerable than other operating systems

Table of Contents

How to Configure Android Compliance Policies in Microsoft Intune

Microsoft Intune compliance policies help organizations ensure that Android devices meet predefined security and compliance requirements before they can access corporate apps, services, and organizational data. These policies evaluate device settings against configured rules and identify whether a device is compliant or noncompliant.

Creating Android compliance policy is an essential part of endpoint security. Administrators can enforce requirements such as password complexity, operating system versions, encryption, security patch levels, and device health checks to reduce security risks and maintain compliance across managed Android devices.

Get Started to Configure Android Compliance Policies

Sign in to the Microsoft Intune admin center using an account with your credentials. From the left navigation pane, select Devices, expand Compliance policies, and then click Create Policies. This page displays all existing compliance policies configured in your Intune tenant.

Patch My PC
How to Configure Android Compliance Policies in Microsoft Intune - Fig.1
How to Configure Android Compliance Policies in Microsoft Intune – Fig.1

In the Create a policy window, select Android Enterprise as the Platform, choose the appropriate Profile type (such as Personally-owned work profile), and then click Create to begin configuring the policy.

How to Configure Android Compliance Policies in Microsoft Intune - Fig.2
How to Configure Android Compliance Policies in Microsoft Intune – Fig.2

Start With Bascis

On the Basics page, enter a descriptive Name and an optional Description for the compliance policy to help identify its purpose. For example, use Android Enterprise Compliance Policy as the policy name and This policy defines compliance requirements for Android Enterprise personally owned work profile devices to ensure they meet organizational security standards before accessing corporate resources as the description. After entering the required information, click Next to continue to the Compliance settings page.

How to Configure Android Compliance Policies in Microsoft Intune - Fig.3
How to Configure Android Compliance Policies in Microsoft Intune – Fig.3

Compliance Settings

The Device Health section contains settings that evaluate the health and integrity of Android devices. Configure the available options according to your organization’s security requirements. The Compliance settings page includes four configuration categories: Microsoft Defender for Endpoint, Device Health, Device Properties, and System Security. Each category provides different options to evaluate the security and compliance status of Android devices.

CategorySetting
Microsoft Defender for EndpointRequire device at or under machine risk score
Device Health: Rooted devicesRooted devices
Require device at or under Device Threat LevelMedium
Google Play ProtectGoogle Play Services configured –Require
Up‑to‑date security provider-Require
Play Integrity Verdict –Check basic integrity & device integrity
Device PropertiesMinimum OS version -6.0
System Security – EncryptionRequire encryption of data storage-Require
System Security – Device SecurityBlock apps from unknown sources – Block
Company Portal app runtime integrity- Require
How to Configure Android Compliance Policies in Microsoft Intune – Table.1
How to Configure Android Compliance Policies in Microsoft Intune - Fig.4
How to Configure Android Compliance Policies in Microsoft Intune – Fig.4

Expand the Microsoft Defender for Endpoint section by clicking the drop-down arrow to view the available settings. For this example, configure Require the device to be at or under the machine risk score and set the value to Medium. This setting helps ensure that only devices with an acceptable Microsoft Defender for Endpoint risk level are considered compliant.

  • Device Health is where the compliance engine checks whether Android devices should be reported. The device health attestation service has many checks, including TPM 2.0 and BitLocker encryption.
  • Device Properties is where Intune Admins define minimum and maximum versions of operating system details for corporate application access. I would keep the minimum version as Android version 6 wherever possible.
    • Operating System Version
    • Minimum Android OS version
    • Maximum Android OS version
  • System Security is the setting where Intune Admins define password policies for Windows devices. These settings have three sections: Password, Encryption, and Device Security.
Password Compliance Policy for Android
Require a password to unlock mobile devices.
Minimum password length
Required password type
Maximum minutes of inactivity before the password is required
Password expiration (days)
Number of previous passwords to prevent reuse
How to Configure Android Compliance Policies in Microsoft Intune – – Table 2
How to Configure Android Compliance Policies in Microsoft Intune - Fig.5
How to Configure Android Compliance Policies in Microsoft Intune – Fig.5

The Actions for noncompliance page allow you to define what happens when an Android device fails to meet the configured compliance requirements. By default, Intune marks a device as noncompliant immediately (0 days), but you can modify the schedule based on your organization’s security policies.

  • The recommended setup is to mark the device noncompliant immediately (0 days) and send a push notification at 0 days, ensuring instant enforcement and user awareness.
How to Configure Android Compliance Policies in Microsoft Intune - Fig.6
How to Configure Android Compliance Policies in Microsoft Intune – Fig.6

Scope Tags

The Scope tags page is optional and is used to control which administrators can view and manage the compliance policy. If your organization does not use custom scope tags, leave the Default scope tag selected and click Next to continue

How to Configure Android Compliance Policies in Microsoft Intune - Fig.7
How to Configure Android Compliance Policies in Microsoft Intune – Fig.7

Assignments for the Compliance Policy

In the Assignments step of your Intune compliance policy, you specify which users or device groups the policy applies to, and the best practice for personally‑owned Android Enterprise. You can also configure exclusion groups if specific users should not receive the policy.

How to Configure Android Compliance Policies in Microsoft Intune - Fig.8
How to Configure Android Compliance Policies in Microsoft Intune – Fig.8

Review + Create Option

Review all configured settings on the Review + Create page to verify that they meet your organization’s compliance requirements. If necessary, return to previous pages to make changes. Once you’ve confirmed the configuration, click Create to deploy the Android compliance policy.

How to Configure Android Compliance Policies in Microsoft Intune - Fig.9
How to Configure Android Compliance Policies in Microsoft Intune – Fig.9

After the policy is successfully created, Microsoft Intune displays a notification confirming that the Android Enterprise compliance policy has been created successfully. You are then redirected to the policy’s Overview or Monitoring page, where you can review the policy details and monitor its compliance status.

How to Configure Android Compliance Policies in Microsoft Intune - Fig.10
How to Configure Android Compliance Policies in Microsoft Intune – Fig.10

Review the Policy Status

After the policy is created, open the newly created compliance policy to review its status. The Monitor tab displays the deployment and compliance status of the policy. Administrators can view the number of compliant, noncompliant, and not evaluated devices, and select the available reports to access detailed compliance information for individual Android devices.

  • Here you can see that the policy Assigned to the groups successfully.
How to Configure Android Compliance Policies in Microsoft Intune - Fig.11
How to Configure Android Compliance Policies in Microsoft Intune – Fig.11

Delete the Android Enterprise Compliance Policy

To delete an Android Enterprise compliance policy, sign in to the Microsoft Intune admin center and navigate to Devices > Compliance policies > Policies. Search for the Android Enterprise compliance policy you want to remove and select it from the list. Click the 3-dot (More) menu next to the policy, and then select Delete. When prompted, confirm the deletion to permanently remove the compliance policy from Microsoft Intune.

How to Configure Android Compliance Policies in Microsoft Intune - Fig.12
How to Configure Android Compliance Policies in Microsoft Intune – Fig.12

How to Setup Intune Compliance Policies for Android

This video guide shows you how to set up Intune compliance policies for Android devices. It provides easy-to-follow instructions for creating policies that ensure your devices meet security standards before accessing company apps and data.

How to Plan Design Intune Compliance Policy for Android Devices – Video 1

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community and WhatsApp Channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows,  Cloud PC, Windows, Entra, Microsoft Security, Career, etc

Leave a Comment