How to Use Intune Compliance Policies to Block Unsupported Devices
Retrospective: this article looks back at events from October 2025, written in 2026 with the benefit of hindsight.
After Windows 10 end of support, unpatched devices shouldn't access company data. Intune compliance policies and Conditional Access can enforce minimum Windows versions. Here is how.
Step 1: Inventory Windows versions
In the Intune admin center, review Devices → Windows and filter by OS version. Also check Defender for Endpoint's device inventory for unmanaged devices.
Step 2: Decide your policy
- Windows 11 required for access to company data.
- Windows 10 allowed only with ESU (devices enrolled and receiving ESU updates).
- Grace period for devices scheduled for upgrade.
Step 3: Create compliance policies
In Devices → Compliance → Create policy → Windows 10 and later:
- Under Device Properties, set Minimum OS version (for example, a Windows 11 build number) — or a minimum Windows 10 build that corresponds to current ESU patch levels.
- Add other requirements: BitLocker, Secure Boot, Defender antimalware, firewall.
- Configure actions for noncompliance: notify users, then mark noncompliant after a grace period.
Step 4: Enforce with Conditional Access
Create a Conditional Access policy requiring device compliance for Microsoft 365 apps and other sensitive resources. Noncompliant devices lose access.
Step 5: Handle exceptions
Some devices (lab equipment, specialized hardware) may not upgrade. Isolate them from corporate data and the internet where possible, and document exceptions with an end date.
Step 6: Accelerate upgrades
Use Windows Autopatch or Intune feature update policies to move eligible devices to Windows 11, and use Endpoint analytics to identify hardware readiness.
Verify
Report the percentage of devices on supported OS versions monthly. Target: 100%, with documented exceptions.
- Windows 10 End of Support (Oct 2025): Unpatched Endpoints in Your Microsoft 365 Estate Platform Changes
- Windows 11 Migration Security Checklist How-To & Hardening
- CIO Brief: The Security Cost of Delaying Windows 11 CIO Briefings