Can I refuse devices that Intune says are not compliant?
Yes, and it is set per client because one client's rules are not another's. There are two settings, not three: ignore the verdict, or refuse a device that fails it. It is only shown for clients set up as Entra ID and Intune; a client on another MDM has no verdict for Passbeam to read.
Ignore is not the same as blind. On ignore, Passbeam still reads Intune's verdict where it can and records it against every authentication, so you can see what enforcing would have done before you turn it on. That is the point of having it as the default — it gives you the evidence first.
It ships set to ignore deliberately. Turning it on is a decision that can lock people off a network they were using five minutes ago, and that is the client's call rather than a default we make for them.
Two limits to know. It only works on device certificates, because a user certificate carries no device identity to look a verdict up against. And it fails open on posture: a device Intune has never evaluated, or one we could not ask about because Microsoft was unreachable, is let on and logged distinctly rather than refused. Identity failures refuse — a certificate that cannot be verified proves nothing — but somebody else's outage must not take a client's whole network offline.
Related questions
Still stuck? Ask us, or read the rest of the knowledge base.