Intune: Windows Health Attestation Migration to Microsoft Azure Attestation
🚨 The Signal: Intune is changing how Windows device health is verified, moving from Device Health Attestation to Azure Attestation. This requires network access to new Azure endpoints to maintain compliance for devices using health-based policies.
The Impact
Security teams and Intune admins are affected, risking non-compliance for Windows devices if network access to new Azure endpoints is not configured.
- Security Teams: Risk of non-compliant devices if network access is not updated.
- Intune Admins: Must configure network rules for new Azure Attestation endpoints.
- Windows Devices: Will fall out of compliance if network access is blocked.
- End Users: May experience restricted access if their device becomes non-compliant.
The Action
- Review current network, firewall, proxy, and endpoint access configurations.
- Identify all Windows devices using Health Attestation-based compliance policies.
- Consult Microsoft guidance for required Azure Attestation endpoints.
- Configure network devices (firewalls, proxies) to allow outbound access to specified Azure Attestation endpoints.
- Validate device compliance after the migration in Q1 2027.
Domain: Intune · Impact: high · Workload: Intune · Essential Eight: Patch Operating Systems, User Application Hardening · ISM: ISM-1407, ISM-1412, ISM-1485, ISM-1486, ISM-1501, ISM-1542, ISM-1585, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1694, ISM-1695, ISM-1696, ISM-1701, ISM-1702, ISM-1823, ISM-1824, ISM-1859, ISM-1860, ISM-1877, ISM-1889, ISM-1902