← What we check

Set compliance policies per platform

DevicesHigh severityNeeds Intune

Without a compliance policy for a given OS, every device on that OS is in 'unknown' compliance state. CA policies that 'require compliant device' silently let those devices through (or block them all, depending on the rule design) because there's no compliance evaluation.

A scan reports where your tenant stands on this check — pass, fail with a step-by-step fix, or not applicable if your licensing doesn’t include the feature. When Tenant Strike can’t read a setting with read-only access, it says unverified and gives you a one-command way to confirm it yourself — it never guesses.

Check your own tenant

Is your tenant covered on "set compliance policies per platform"?

One read-only scan answers it — this check and every other one in the catalog, each with a plain-English fix. 7-day Pro trial, no credit card.