Skip to main content

📚🪟💻Compliance - Device Health - Code Integrity

What this policy is about 🔍

Code Integrity ensures that only trusted, signed code runs on your devices.

This compliance policy checks whether Hypervisor-Protected Code Integrity (HVCI) is enabled. HVCI uses virtualization-based security to protect the kernel from running unsigned or malicious drivers.

Without it, malware can load malicious drivers that operate at kernel level—bypassing most security tools.


How it works 🛠️

This policy uses Windows Device Health Attestation to verify Code Integrity status.

  1. TPM chip reports status — Confirms HVCI/Code Integrity is enabled
  2. Windows Health Attestation Service — Microsoft verifies the report
  3. Intune receives the result — Compliant or non-compliant

This is hardware-backed attestation. The device cryptographically proves its security state.


🛠️ Compliance Settings

Platform

  • Windows 10 and later

Profile Type

  • Windows 10/11 compliance policy

Device Health

SettingValue
Require Code IntegrityRequired

⚙️ Actions for Non-Compliance

ActionScheduleMessage TemplateAdditional Recipients
Mark device non-compliantImmediately(none)None selected

👥 Group Assignments

✅ Included groups:

  • All Devices

❌ Excluded groups: