Skip to content
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS

Written By Anoop C Nair
Last Updated June 25, 2026
Posted In Intune
SHARE

Key Takeaways

  • Understand the purpose and benefits of Intune Compliance Policies for iOS devices.
  • Learn how to create and configure an iOS compliance policy in Microsoft Intune.
  • Configure compliance settings, including password requirements, device health, OS version, and system security.
  • Deploy the compliance policy to the appropriate Microsoft Entra user groups.

Let’s discuss setting up an Intune Compliance Policy for iOS Devices. This post will explain how to do so. An Intune Compliance Policy ensures that iOS devices accessing company data meet specific security standards. Enforcing these policies can help protect your organization’s data from unauthorized access and potential security threats. The organization must ensure that the devices that access company apps and data comply with specific rules.

Table of Contents

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS

These rules might include using a password/PIN to access devices and encrypting data stored on devices. This set of such rules is called a compliance policy. The best option is to use a compliance policy with Intune Conditional Access. A compliance policy is a set of guidelines that devices must meet to access organizational resources. It ensures that only secure and compliant devices can access company data, reducing the risk of data breaches or unauthorized access.

How to Setup Intune Compliance Policies for iOS

Sign in to the Microsoft Intune admin center and navigate to Devices > Compliance > Policies. Click + Create Policy to create a new compliance policy.

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.1
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.1

Select iOS/iPadOS as the platform, and then click Create. This opens the policy creation wizard, where you can define the compliance requirements that iOS devices must satisfy before accessing organizational resources.

Patch My PC
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.2
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.2

Start with Basic Tab

On the Basics page, enter a descriptive Name and an optional Description for the compliance policy. Using a meaningful name, such as iOS Compliance Policy – Corporate Devices, makes it easier to identify and manage the policy in environments with multiple compliance policies. After entering the required information, click Next.

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.3
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.3

How Do you Set up the Intune Compliance Policy for iOS?

The Compliance Settings page allows you to define the security requirements that iOS and iPadOS devices must meet to be considered compliant. Configure the settings according to your organization’s security policies. The available categories include:

  1. iOS compliance policies have 4 categories: Email, Device Health, Device Properties, and System Security.
  2. Email settings require mobile devices to have a managed email profile to access corporate resources.
  3. The device Health setting will check whether the device is jailbroken or not. If the iOS device is Jailbroken, it won’t provide mail access to that device.
  4. The device Properties setting will check the OS version of the device and the minimum version of the iOS OS.
  5. The System Security setting is based mainly on password settings. There are some improvements over the Intune Silverlight portal here. We can have the option not to configure some of the settings, like “Number of non-alphanumeric characters in password.” This was not possible with the Intune Silverlight portal.
How to Setup Intune Compliance Policy for iOS?
Require a password to unlock mobile devices.
Simple passwords
Minimum password length
Not ConfiguredAlphanumericNumeric
Number of non-alphanumeric characters in the password
Maximum minutes of inactivity before a password is required
Password expiration (days)
Number of previous passwords to prevent reuse
HStep-by-Step Guide to Configuring Intune Compliance Policies for iOS – Table 1
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.4
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.4

Actions for Noncompliance

On the Actions for Noncompliance page, specify what happens when a device fails to meet the compliance requirements. By default, Intune marks the device as non-compliant immediately, which can be used together with Microsoft Entra Conditional Access to block access to corporate resources.

The first action, Mark device noncompliant (0 days), flags the device immediately so Conditional Access can restrict corporate access. The second action, remotely lock the noncompliant device (3 days), automatically locks the device if it remains noncompliant for three days, forcing the user to re‑enter their passcode before regaining access.

  • This combination gives users time to fix issues while maintaining security. Once these actions are configured, click Next
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.5
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.5

Scope Tags

The Scope tags page is optional and is used to control which administrators can view and manage the compliance policy. If your organization does not use custom scope tags, leave the Default scope tag selected and click Next to continue.

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.6
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.6

Assignment Section

On the Assignments page, select the Microsoft Entra user groups that will receive the compliance policy. Assigning the policy to user groups ensures that all eligible iOS devices enrolled by those users are evaluated against the configured compliance settings.

  • Review the selected groups carefully before proceeding, and then click Next.
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.7
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.7

Review + Create

The Review + Create page displays a summary of all configured settings, including the policy name, compliance rules, noncompliance actions, and assignments. Review the configuration to verify that it matches your organization’s security requirements. Once you have confirmed that everything is configured correctly, click Create to deploy the compliance policy. Intune will begin applying the policy to the targeted users.

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.8
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.8

How to Find Out the Compliance Policy

Navigate to Devices > Compliance in the Intune Admin Center. Use the search box to locate the required iOS/iPadOS Compliance policy by entering its name. Once the policy appears in the list, select it to open the policy details.

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.9
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.9

Review the Policy Status

After opening the compliance policy, the Monitor tab displays the deployment status. Here, administrators can review the number of Compliant, Noncompliant, and Other devices assigned to the policy. Select View report to access detailed compliance information for individual devices.

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.10
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.10

Delete the Compliance Policy

Go to Devices > Compliance and search for the compliance policy. From the policy list, locate the required policy, select the 3-dot (More) menu next to it, and choose Delete. Confirm the deletion when prompted to permanently remove the compliance policy from Intune.

Step-by-Step Guide to Configuring Intune Compliance Policies for iOS - Fig.11
Step-by-Step Guide to Configuring Intune Compliance Policies for iOS – Fig.11

Video

In this video, you will learn all the details on how to set up Intune compliance policies for iOS devices. We’ll guide you through creating and configuring these policies to ensure your company’s data remains secure.

How to Setup Intune Compliance Policy for iOS Devices – Video 1

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community and WhatsApp Channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows,   Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 5 comments

  1. i’m trying to set PIN on iOS Device with the simple password not permitted. Why the combination 307989 is considered too simple? thanks

  2. Great writeup but should include images of the end user experience on the phone.

    Thanks Anoop! Great articles.

  3. I get “This Action is not allowed by your organisation” when trying to open a document attachment in Outlook for Android.

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read