Intune Device Not Compliant


Description

Microsoft Intune allows administrators to manage devices and enforce compliance with established policies. This detection identifies devices that are not compliant with the established policies.

Query · python

HOSTNAME = ""


def rule(event):

    return all(
        [
            event.get("operationName", "").lower() == "compliance",
            event.deep_get("properties", "AlertType", default="").lower()
            == "managed device not compliant",
        ]
    )


def title(event):
    # pylint: disable=global-statement
    global HOSTNAME

    # Simple title with hostname of the non-compliant device
    HOSTNAME = event.deep_get("properties", "DeviceHostName", default="Unknown")

    return f"INTUNE: [{HOSTNAME}] reported as non-compliant"


def alert_context(event):
    return {
        "Hostname": HOSTNAME,
        "Operating System": event.deep_get(
            "properties", "DeviceOperatingSystem", default="Unknown"
        ),
        "User": event.deep_get("properties", "UserName", default="Unknown"),
        "User Display Name": event.deep_get("properties", "UserDisplayName", default="Unknown"),
        "Description": event.deep_get("properties", "Description", default="Unknown"),
    }

Analyst notes

Review the Description field for information about the policy that the device is not compliant with. This is typically easier to review and investigate in the Intune portal.

Raw source Intune Device Not Compliant · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: intune_device_not_compliant.py
RuleID: "Intune.DeviceNotCompliant"
DisplayName: "Intune Device Not Compliant"
Enabled: true
LogTypes:
    - MicrosoftIntune.OperationalLogs
Tags:
    - InTune
Severity: Low
Reports:
    MITRE ATT&CK:
        - "TA0005:T1652"
Description: Microsoft Intune allows administrators to manage devices and enforce compliance with established policies. This detection identifies devices that are not compliant with the established policies.
Runbook: Review the Description field for information about the policy that the device is not compliant with. This is typically easier to review and investigate in the Intune portal.
DedupPeriodMinutes: 60
Threshold: 1
Reference: https://learn.microsoft.com/en-us/intune/intune-service/protect/compliance-policy-monitor
Tests:
    - Name: Device Reported Not Compliant
      ExpectedResult: true
      Log:
          {
              "category": "OperationalLogs",
              "operationName": "Compliance",
              "properties":
                  {
                      "AADTenantId": "11111111-2222-3333-4444-555555555555",
                      "AlertDisplayName": "Managed Device TestDevice_8/2/2024_6:32 PM is not Compliant",
                      "AlertType": "Managed Device Not Compliant",
                      "Description": "DefaultDeviceCompliancePolicy.RequireRemainContact||DefaultDeviceCompliancePolicy.RequireRemainContact||DefaultDeviceCompliancePolicy.RequireRemainContact||Expected recent contact. Last contact: 2025-03-27 17:35:40Z||2025-03-27 17:35:40Z||ComplianceCalculation",
                      "DeviceDnsDomain": "",
                      "DeviceHostName": "TestDevice",
                      "DeviceName": "TestDevice_8/2/2024_6:32 PM",
                      "DeviceNetBiosName": "TestDevice",
                      "DeviceOperatingSystem": "Windows 10.0.26100.2894",
                      "IntuneAccountId": "11111111-2222-3333-4444-555555555555",
                      "IntuneDeviceId": "11111111-2222-3333-4444-555555555555",
                      "IntuneUserId": "11111111-2222-3333-4444-555555555555",
                      "OperationalLogCategory": "DeviceCompliance",
                      "ScaleUnit": "AMSUA0602",
                      "ScenarioName": "Microsoft.Management.Services.Diagnostics.SLAEvents.DeviceNotInComplianceSecurityAlert",
                      "StartTimeUtc": "2025-04-02T05:57:59.4097Z",
                      "UPNSuffix": "test.com",
                      "UserDisplayName": "Device Enrollment Manager",
                      "UserName": "testuser",
                  },
              "resultType": "None",
              "tenantId": "11111111-2222-3333-4444-555555555555",
              "time": "2025-04-02T05:57:59.4097000Z",
          }
    - Name: Device Enrollment
      ExpectedResult: False
      Log:
          {
              "category": "OperationalLogs",
              "operationName": "Enrollment",
              "properties":
                  {
                      "AADDeviceId": "11111111-2222-3333-4444-555555555555",
                      "AADTenantId": "11111111-2222-3333-4444-555555555555",
                      "EnrollmentTimeUTC": "2025-04-09T15:59:08.5840Z",
                      "EnrollmentType": "WindowsAzureADJoin",
                      "FailureCategory": "Not Applicable",
                      "FailureReason": "Unknown",
                      "IntuneAccountId": "11111111-2222-3333-4444-555555555555",
                      "IntuneDeviceId": "11111111-2222-3333-4444-555555555555",
                      "IntuneUserId": "11111111-2222-3333-4444-555555555555",
                      "MessageId": "11111111-2222-3333-4444-555555555555",
                      "OperationalLogCategory": "DeviceEnrollment",
                      "Os": "Windows",
                      "OsVersion": "10.0.26100.1742",
                      "ScaleUnit": "AMSUA0602",
                      "ScenarioName": "Microsoft.Management.Services.Diagnostics.SLAEvents.EnrollmentSLAEvent",
                  },
              "resultType": "Success",
              "tenantId": "11111111-2222-3333-4444-555555555555",
              "time": "2025-04-09T15:59:08.5840000Z",
          }


# ------ paired body: intune_device_not_compliant.py ------

HOSTNAME = ""


def rule(event):

    return all(
        [
            event.get("operationName", "").lower() == "compliance",
            event.deep_get("properties", "AlertType", default="").lower()
            == "managed device not compliant",
        ]
    )


def title(event):
    # pylint: disable=global-statement
    global HOSTNAME

    # Simple title with hostname of the non-compliant device
    HOSTNAME = event.deep_get("properties", "DeviceHostName", default="Unknown")

    return f"INTUNE: [{HOSTNAME}] reported as non-compliant"


def alert_context(event):
    return {
        "Hostname": HOSTNAME,
        "Operating System": event.deep_get(
            "properties", "DeviceOperatingSystem", default="Unknown"
        ),
        "User": event.deep_get("properties", "UserName", default="Unknown"),
        "User Display Name": event.deep_get("properties", "UserDisplayName", default="Unknown"),
        "Description": event.deep_get("properties", "Description", default="Unknown"),
    }

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.