Stop Chasing Intune Noncompliance Across Three Different Exports
Build one focused triage packet that shows which devices failed, their inventory and health context, and where an administrator should investigate next.
A red compliance count is not a remediation plan. Teams lose time downloading one list for devices, another for assignments, and another for health, then trying to match names that may have changed.
Use PSForge to generate a repeatable evidence-gathering workflow around a deliberately small device group. The outputs narrow the investigation, but they do not establish compliance by themselves and they do not replace review of the actual policy failure.
Prerequisites and boundaries
Confirm Graph permissions, export locations, the policy owner, and a pilot group. Define the review window and the fields used to join reports, such as device ID rather than display name.
- Do not weaken a compliance policy to clear a dashboard.
- Do not send a broad sync until the target list is reviewed.
- Preserve original exports before adding analyst notes.
Gather evidence before taking action
Export the noncompliant-device report, overall compliance report, inventory, and device health. Correlate them manually by stable identifiers. Inspect each affected device's compliance-policy assignment in the Intune admin center, because the generated exports do not report those assignments. Separate stale records, recently enrolled devices, unhealthy devices, and genuine policy failures into different queues.
Use a controlled retry and verify
After the owner fixes the underlying condition, sync only an approved device and rerun the exports. Compare timestamps and policy state with the baseline. The administrator—not PSForge—decides whether the issue is resolved or needs escalation.
Evidence, not a verdict Generated reports document observed Intune state at collection time. They do not prove a device remained compliant before or after that moment.
Example noncompliance triage
- Export noncompliant devices and compliance summary
- Export inventory and health details
- Check compliance-policy assignments manually
- Join records by device ID
- Manually approve one-device remediation
- Sync that device and compare fresh evidence
Final thoughts
The useful outcome is not a prettier red-device list; it is a defensible queue with enough context to act safely.
Rerun the same evidence steps after remediation so before-and-after state stays attached to the work item.