Announcement

Intune Adds Client-Driven Compliance Evaluation for Windows (Preview)

Seven specific compliance signals on Windows devices now trigger a re-evaluation in near real time instead of waiting for the next scheduled check-in. Everything else still runs on the old cycle, and there's built-in throttling most write-ups have missed.

Action required No configuration needed for supported Windows devices. If your compliance troubleshooting docs or helpdesk scripts assume only scheduled check-ins, update them: seven specific signals now trigger a re-evaluation in near real time instead.

A device gets remediated, BitLocker finishes encrypting, the firewall gets turned back on, and the user still sits blocked from Microsoft 365 because Intune hasn’t caught up yet. That specific wait is what Microsoft’s new capability targets, for seven signals, not for compliance policy in general.

Microsoft describes it under Week of September 14, 2026 in What’s new in Microsoft Intune: “Faster compliance updates for Windows devices.” The technical detail sits in the Create a compliance policy and Windows compliance settings articles, both updated within the last week.

Key Takeaways

  • Windows devices can now proactively request a compliance re-evaluation the moment a supported signal changes, instead of waiting for the next scheduled check-in
  • Only seven specific signals get this fast path: Firewall, Antivirus, BitLocker, Microsoft Defender status, OS build version, Real-time protection, and Secure Boot
  • Everything else, including custom compliance scripts, still relies on the existing Intune Management Extension’s periodic scheduled monitoring
  • Intune throttles compliance-triggered re-evaluations, so a burst of changes in a short window doesn’t all land instantly
  • No extra licensing required beyond your existing Intune subscription. Conditional Access, if you use it, still needs Entra ID P1 or P2 as before, unrelated to this change

Two monitoring mechanisms, not one

Microsoft’s documentation describes this as two separate mechanisms working side by side, and the distinction matters more than the marketing framing of “faster compliance” suggests. Scheduled compliance monitoring is the existing behavior: the Intune Management Extension periodically checks monitored settings against a stored baseline, and if something changed, it triggers a check-in on its own schedule. Real-time compliance monitoring is the new piece, and it’s narrower: for a specific, named list of Windows settings, Intune watches for the change directly and “proactively requests a device check-in” the moment it happens, rather than waiting for the IME’s next scheduled pass.

The framing worth correcting: this isn’t Intune compliance getting faster across the board. It’s a fast lane added next to the existing slow lane, open to exactly seven settings. A custom compliance script, a Configuration Manager co-management setting, or anything outside that named list still moves at the same speed it always did, through the Intune Management Extension’s periodic scheduled checks. If your remediation workflow depends on a setting that isn’t on the list below, this update changes nothing for you.

The seven signals

Quoted directly from Microsoft’s own list of what’s “monitored through real-time event detection”:

  • Firewall
  • Antivirus
  • BitLocker
  • Microsoft Defender status
  • Operating system build version
  • Real-time protection (RTP)
  • Secure Boot

Change one of these on a supported Windows device, and Intune detects it and requests a check-in on its own, without the device having to wait for its next scheduled sync interval.

What this doesn’t do

The most common assumption I’d expect to see once this rolls out is “my device isn’t updating fast enough, so I’ll just tell the user to hit sync in Company Portal,” when the actual fix is confirming the specific setting that changed is even one of the seven this update covers. A password policy change, a custom compliance script result, an OS setting outside this list: none of that gets the real-time path. It still needs either a manual sync or the scheduled monitoring cycle to catch up.

Microsoft’s own documentation also flags a limit worth planning around: “Intune uses built-in throttling for compliance-triggered reevaluations. If multiple changes occur in a short period, some updates might be processed during subsequent evaluation cycles.” A device that toggles several of these settings in quick succession (a compliance remediation script that fixes BitLocker, the firewall, and Defender in the same run, for instance) won’t necessarily get seven instant re-evaluations. Some of those updates fall back to the next scheduled cycle anyway.

What you need to do

Nothing to configure. This applies automatically to supported Windows devices once the preview reaches your tenant, on top of whatever compliance policies you already have assigned. The two things actually worth doing:

  1. Update any internal documentation or helpdesk scripts that describe compliance sync as purely schedule-based. For these seven signals specifically, that’s no longer accurate.
  2. Don’t expect it to fix reporting delays for settings outside the list. If a specific compliance rule still feels slow to update, check first whether it’s one of the seven before assuming something’s broken.

Frequently Asked Questions

Do we need a new license for this?

No. It requires your existing Microsoft Intune subscription, the same as any other compliance policy. If you use Conditional Access with compliance status, that still needs Microsoft Entra ID P1 or P2 as it always has, unrelated to this specific capability.

Does this cover custom compliance scripts?

Not based on what Microsoft’s documentation currently describes. The real-time detection list is limited to the seven named settings. Custom compliance settings continue to rely on the existing scheduled monitoring cycle through the Intune Management Extension.

Is this generally available or still preview?

Microsoft’s own heading for the underlying feature is “Client-driven compliance evaluation (preview).” Treat it as preview functionality: available now for supported Windows devices, but not yet a finalized, fully documented capability.

Will this cause a flood of check-ins if several settings change at once?

Microsoft explicitly documents throttling for this scenario. If multiple monitored changes happen in a short window, not all of them trigger an immediate re-evaluation. Some get picked up on the next scheduled cycle instead.

← All announcements