> For the complete documentation index, see [llms.txt](https://docs.cipp.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cipp.app/user-documentation/endpoint/mem/list-compliance-policies.md).

# Compliance Policies

Lists the device compliance policies on the selected tenant, showing what type each policy is and who it is assigned to. Compliance policies define the conditions a device must meet to be considered compliant, which conditional access and other controls can then act on.

## Action Buttons

<details>

<summary>Deploy Policy</summary>

Opens a drawer that applies a saved policy template to one or more tenants.

| Field                              | Description                                                                                                                                                             |
| ---------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Select Tenants                     | The tenants to deploy to. Several can be selected, and the same template is applied to each.                                                                            |
| Please choose a template to apply. | The policy template to deploy, chosen from those saved in Policy Templates. **Refresh Templates** reloads the list if a template was added since the drawer was opened. |
| Assignment                         | Who the deployed policy is assigned to: Do not assign, Assign to all users, Assign to all devices, Assign to all users and devices, or Assign to Custom Group.          |
| Custom Group Names                 | Shown when Assign to Custom Group is chosen. Group display names separated by commas, where `*` may be used as a wildcard.                                              |
| Exclude Group Names                | Shown for every option except Do not assign. Group display names to exclude, again comma separated and accepting `*` as a wildcard.                                     |
| Assignment Filter (Optional)       | An assignment filter from the tenant to narrow which devices the policy applies to.                                                                                     |
| Assignment Filter Mode             | Whether the filter includes or excludes matching devices. Shown once a filter is chosen.                                                                                |

The template's configuration is displayed below the picker so it can be checked before deploying.

{% hint style="info" %}
Where the template contains variables written as `%name%`, the drawer asks for a value for each one, per tenant, before it will deploy. `%tenantid%` and `%tenantdomain%` are filled in automatically for each selected tenant.
{% endhint %}

{% hint style="warning" %}
Deploying a template does not always create a new policy. CIPP first looks for a policy in the target tenant whose name exactly matches the template's, and where one is found it overwrites that policy in place. A new policy is only created where no match exists.

Because the match is on the name alone, a policy created by hand under the same name will be overwritten, and a deployed policy that has since been renamed in Intune will not be recognised, so the next deployment creates a duplicate alongside it. Where two policies share a name, the more recently modified one is the one overwritten.

The assignment chosen here is added to the policy's existing assignments rather than replacing them.
{% endhint %}

{% hint style="danger" %}
What an overwrite does to settings the template does not mention depends on the policy type.

For Settings Catalog and Administrative Templates this means any change made directly in the Microsoft Intune admin center since the template was captured is lost on the next deployment.
{% endhint %}

| Policy type              | Settings not present in the template                                                          |
| ------------------------ | --------------------------------------------------------------------------------------------- |
| Settings Catalog         | Removed. The policy's settings become exactly what the template holds.                        |
| Administrative Templates | Removed. Every configured setting on the policy is cleared before the template's are applied. |
| All other types          | Left as they are. The template's settings are merged over the existing ones.                  |

</details>

## Table Details

| Column                  | Description                                                                                                                                  |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Display Name            | The name of the policy.                                                                                                                      |
| Policy Type Name        | The platform the policy applies to, for example Windows 10/11 Compliance, iOS Compliance, macOS Compliance or Android Enterprise Compliance. |
| Policy Assignment       | The groups and broad targets the policy is assigned to. All Devices and All Licensed Users appear here where those targets are used.         |
| Policy Exclude          | The groups excluded from the policy.                                                                                                         |
| Description             | The description recorded against the policy.                                                                                                 |
| Last Modified Date Time | When the policy was last changed.                                                                                                            |

The remaining properties, available from the column chooser and in the row flyout, are those of the Graph resource type `deviceCompliancePolicy`. For more information on the properties please see the [Graph documentation](https://learn.microsoft.com/en-us/graph/api/resources/intune-shared-devicecompliancepolicy?view=graph-rest-beta#properties).

## Table Actions

<table><thead><tr><th>Action</th><th>Description</th><th width="250" data-type="checkbox">Bulk Action Available</th></tr></thead><tbody><tr><td>Create template based on policy</td><td>Creates a policy template based on the selected policy(ies)</td><td>true</td></tr><tr><td>Edit Name &#x26; Description</td><td>Allows you to edit the name and description of the selected policy(ies)</td><td>true</td></tr><tr><td>Clone Policy</td><td>Creates a clone of the selected policy(ies) with the ability to set a new name and description</td><td>true</td></tr><tr><td>Assign to All Users</td><td>Assigns the policy(ies) to all users, with optional exclusion groups and an optional assignment filter</td><td>true</td></tr><tr><td>Assign to All Devices</td><td>Assigns the policy(ies) to all devices, with optional exclusion groups and an optional assignment filter</td><td>true</td></tr><tr><td>Assign Globally (All Users / All Devices)</td><td>Assigns the policy(ies) to all users and all devices, with optional exclusion groups and an optional assignment filter</td><td>true</td></tr><tr><td>Assign to Custom Group</td><td>Assigns the policy(ies) to a custom group from the tenant. Options are to include or exclude the group and replace or append to existing assignments. You can also apply an existing assignment filter to further restrict assignment.</td><td>true</td></tr><tr><td>Delete Policy</td><td>Deletes the selected policy(ies)</td><td>true</td></tr><tr><td>More Info</td><td>Opens the Extended Info flyout</td><td>false</td></tr></tbody></table>

***

## Feature Requests / Ideas

We value your feedback and ideas. Please raise any [feature requests](https://github.com/CyberDrain/CIPP/issues/new?template=feature.yml) on GitHub.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cipp.app/user-documentation/endpoint/mem/list-compliance-policies.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
